Impact
This vulnerability allows an attacker with low privilege and network access to send crafted SOAP requests to the Siebel CRM Integration component, resulting in unauthorized access to critical data, full read of all integration data, and the ability to insert, update, or delete records. The weakness is a flaw in access control, classified as CWE‑284 (Improper Access Control), leading to confidentiality loss and a partial integrity compromise, as reflected in the CVSS vector with high confidentiality impact and low integrity impact.
Affected Systems
The flaw affects Oracle Siebel CRM Integration versions 17.0 through 26.7, as distributed by Oracle Corporation under the Siebel CRM Integration product. Only these supported releases are vulnerable.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate to high severity vulnerability; the EPSS score of less than 1% suggests low probability of widespread exploitation at this time. The flaw is not listed in CISA’s KEV catalog. Exploitation requires network access to the SOAP service and can be carried out by an attacker who already holds low‑privileged credentials, implying that if such credentials are compromised or improperly scoped, the attacker can fully compromise data confidentiality and integrity within the integration scope.
OpenCVE Enrichment