Impact
The vulnerability allows an unauthenticated party with network access to the Siebel CRM Deployment product to trigger a full denial‑of‑service by repeatedly causing the system to hang or crash. The weakness, classified as CWE‑400, arises from uncontrolled resource consumption that results in an availability impact when an attacker sends malicious TCP traffic to the server infrastructure component. This flaw can be exercised without authentication and can be repeated until the product becomes non‑operational, preventing legitimate users from accessing services.
Affected Systems
Affected versions of the Oracle Siebel CRM Deployment product range from 17.0 through 26.7. The vulnerability is relevant to installations of these versions and applies to the server infrastructure component of Siebel CRM. The issue is not confined to a specific configuration but generally impacts any deployment that exposes the affected services over the network.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity primarily on availability. The EPSS score of <1% suggests a very low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. However, the attack vector is network‑based via TCP and requires no authentication, making it trivially exploitable for any host exposed to potentially hostile networks. Organizations with accessible deployments should promptly evaluate the risk and plan remediation steps.
OpenCVE Enrichment