Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

This vulnerability in Oracle Siebel CRM Deployment allows an unauthenticated attacker to send specially crafted input over a TCP connection, resulting in uncontrolled resource consumption that forces the application to hang or crash. The weakness exploits a resource exhaustion flaw, classified as CWE‑400, and has no impact on confidentiality or integrity. Successful exploitation leads to a denial of service that can occur repeatedly as the system repeatedly enters a crash state.

Affected Systems

The affected product is Oracle Siebel CRM Deployment for the Server Infrastructure component. Versions from 17.0 through 26.7 are vulnerable and must be examined for current deployment configurations.

Risk and Exploitability

The CVSS v3.1 Base Score is 7.5, indicating a high severity for availability impact. The EPSS score is below 1%, suggesting limited evidence of active exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack can be carried out from any network host with TCP access to the Siebel CRM Deployment services, without authentication. Because the exploitation requires only network connectivity and permits only denial of service, the likelihood of a successful attack in environments lacking network segmentation is non‑negligible, while impacts are limited to service interruption.

Generated by OpenCVE AI on September 18, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict TCP access to Siebel CRM Deployment to trusted hosts only using firewall or network ACL rules.
  • Monitor application logs for repeated hang or crash events and configure alerting for abnormal shutdown patterns.
  • Check Oracle’s security alerts regularly for an official patch or update, and apply it as soon as it becomes available.

Generated by OpenCVE AI on September 18, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle siebel Crm
CPEs cpe:2.3:a:oracle:siebel_crm:*:*:*:*:*:*:*:*
Vendors & Products Oracle siebel Crm

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Denial of Service in Oracle Siebel CRM Deployment

Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Denial of Service in Oracle Siebel CRM Deployment

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Siebel Crm Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T23:14:53.881Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83228

cve-icon Vulnrichment

Updated: 2026-09-15T23:13:11.836Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:34.630

Modified: 2026-09-21T16:15:54.910

Link: CVE-2026-83228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:15:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption