Impact
The vulnerability allows an attacker with low privileges and network access over HTTP to compromise the integration, potentially leading to takeover of the entire system. This would compromise confidentiality, integrity, and availability, giving the attacker full administrative access.
Affected Systems
Affected systems are Oracle Siebel CRM Integration products manufactured by Oracle Corporation, specifically the EAI component running versions 17.0 through 26.7. Networks that expose this component over HTTP are at risk. The vulnerability is documented for the Oracle Siebel CRM Integration CPE identifier.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates high severity, while the EPSS value of less than 1% suggests a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. However, the vulnerability requires network access via HTTP, a high complexity attack, and low privilege. An attacker who succeeds can take over the entire integration component, possibly leading to a full system compromise.
OpenCVE Enrichment