Impact
This vulnerability resides in the Siebel Management Console component of Oracle Siebel CRM Deployment. A low-privileged attacker who can reach the system over HTTP can exploit insufficient access control, enabling the attacker to read confidential data and to update, insert or delete data. The weakness is an improper access control flaw that directly compromises confidentiality and integrity.
Affected Systems
The affected product is Oracle Siebel CRM Deployment, specifically its Siebel Management Console component. Oracle lists supported versions 17.0 through 26.7 as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a moderate-to-high severity. Although the EPSS score is less than 1%, implying a low likelihood of exploitation at the time of analysis, the impact of successful exploitation is significant, exposing critical data and allowing unauthorized modification. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is network-based HTTP access to the Siebel Management Console, requiring only low privileges to succeed.
OpenCVE Enrichment