Impact
The vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment allows a low‑privileged attacker with network access via HTTP to compromise the system. Exploitation can lead to unauthorized access to critical or all accessible data and can cause a partial denial of service, impacting confidentiality and availability. The vulnerability is rooted in improper access control and authentication bypass mechanisms, corresponding to CWE-284.
Affected Systems
Affected are the Oracle Siebel CRM Deployment product for all supported versions from 17.0 through 26.7. Any environment running these releases and exposed to HTTP traffic is potentially vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 exploit requiring only low privilege and network connectivity to an HTTP interface. The EPSS score of <1% suggests a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The weakness involves improper access control and authentication issues (CWE-284). The likely attack vector is a network-facing HTTP endpoint that accepts connections from untrusted hosts; based on the description it is inferred that the attacker does not need high‑level credentials but can abuse a low‑privileged or guest user profile to gain access.
OpenCVE Enrichment