Impact
A vulnerability classified as CWE-284 exists in Oracle Siebel CRM Deployment that permits a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to complete takeover, compromising confidentiality, integrity and availability of the entire application. The weakness is a flaw in the server infrastructure that allows unauthorized privileged actions when HTTP requests are received.
Affected Systems
The affected vendor is Oracle Corporation, product Siebel CRM Deployment. Versions 17.0 through 26.7 are impacted. Only deployments of these versions are at risk, while newer releases are not listed as vulnerable.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high overall severity. The EPSS score is slightly below 1%, indicating a low but non‑zero likelihood that the flaw will be targeted in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request, with a low privileged attacker able to trigger the exploit and gain system‑level control.
OpenCVE Enrichment