Impact
The vulnerability in Oracle Siebel CRM Deployment allows an unauthenticated attacker with network connectivity to trigger a hang or crash of the application, causing complete service disruption. It is a classic resource exhaustion flaw, classified as CWE-400, with a CVSS 3.1 Base Score of 7.5 that reflects a high availability impact.
Affected Systems
This flaw affects the Siebel CRM Deployment product, component Server Infrastructure, on versions ranging from 17.0 up to and including 26.7. Administrators managing these environments should verify the exact build number of their installations.
Risk and Exploitability
The exploitation vector requires only network access and no authentication; the attack can occur over multiple protocols exposed by the deployment. The EPSS score of less than 1% indicates that the current likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog, suggesting no major widespread attacks have been observed. Nevertheless, an successful exploit would restrict availability for the affected application, potentially impacting business operations.
OpenCVE Enrichment