Impact
This vulnerability in Oracle Siebel CRM Deployment allows an unauthenticated attacker to send specially crafted input over a TCP connection, resulting in uncontrolled resource consumption that forces the application to hang or crash. The weakness exploits a resource exhaustion flaw, classified as CWE‑400, and has no impact on confidentiality or integrity. Successful exploitation leads to a denial of service that can occur repeatedly as the system repeatedly enters a crash state.
Affected Systems
The affected product is Oracle Siebel CRM Deployment for the Server Infrastructure component. Versions from 17.0 through 26.7 are vulnerable and must be examined for current deployment configurations.
Risk and Exploitability
The CVSS v3.1 Base Score is 7.5, indicating a high severity for availability impact. The EPSS score is below 1%, suggesting limited evidence of active exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack can be carried out from any network host with TCP access to the Siebel CRM Deployment services, without authentication. Because the exploitation requires only network connectivity and permits only denial of service, the likelihood of a successful attack in environments lacking network segmentation is non‑negligible, while impacts are limited to service interruption.
OpenCVE Enrichment