Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Oracle Siebel CRM Deployment allows an unauthenticated attacker with network connectivity to trigger a hang or crash of the application, causing complete service disruption. It is a classic resource exhaustion flaw, classified as CWE-400, with a CVSS 3.1 Base Score of 7.5 that reflects a high availability impact.

Affected Systems

This flaw affects the Siebel CRM Deployment product, component Server Infrastructure, on versions ranging from 17.0 up to and including 26.7. Administrators managing these environments should verify the exact build number of their installations.

Risk and Exploitability

The exploitation vector requires only network access and no authentication; the attack can occur over multiple protocols exposed by the deployment. The EPSS score of less than 1% indicates that the current likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog, suggesting no major widespread attacks have been observed. Nevertheless, an successful exploit would restrict availability for the affected application, potentially impacting business operations.

Generated by OpenCVE AI on September 16, 2026 at 21:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Siebel CRM Deployment to a version newer than 26.7 or apply the official Oracle security patch for this flaw.
  • Restrict inbound network access to the deployment server, allowing only trusted IP ranges or authenticated VPN connections to the protocols that the application uses.
  • Disable or block any unused or unnecessary network protocols that the application listens on, and monitor logs for suspicious activity related to the crash trigger.

Generated by OpenCVE AI on September 16, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Denial of Service Attack Against Oracle Siebel CRM Deployment via Unauthenticated Network Access

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:54.200Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83222

cve-icon Vulnrichment

Updated: 2026-09-15T23:13:18.576Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:33.947

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:45:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption