Impact
The vulnerability lies in the Siebel Remote component of Oracle Siebel CRM Deployment. It allows an attacker with low privileges and network connectivity via HTTP to exploit a flaw that ultimately grants the attacker the ability to compromise the deployment. Successful exploitation results in full takeover and loss of confidentiality, integrity and availability of all data and services managed by the system. The weakness is a form of improper access control.
Affected Systems
Oracle Corporation's Siebel CRM Deployment product, specifically versions 17.0 through 26.7, is affected.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests that exploitation attempts are rare and the vulnerability is not listed in CISA KEV. The attack vector most likely involves a crafted HTTP request sent to the Siebel Remote endpoint from a low‑privileged host. Although the flaw is difficult to exploit, once triggered the attacker can control the deployment and all underlying data.
OpenCVE Enrichment