Impact
The vulnerability resides in the Event Publish and Subscribe component of Oracle Siebel CRM Integration. An unauthenticated attacker who can connect to the physical communication segment attached to the hardware where the product runs can exploit the flaw to create, delete, or modify critical data. These actions compromise data confidentiality and integrity for all data accessible through the integration, but no direct availability impact is identified.
Affected Systems
The affected product is Oracle Siebel CRM Integration, with all supported releases from 23.6 through 26.7 vulnerable. The flaw is tied to the physical communication interface used by the integration, meaning that the threat is limited to a local or physically proximate environment.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity for confidentiality and integrity. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or physically proximate attacker with access to the hardware's communication segment; no network or remote attack is required.
OpenCVE Enrichment