Impact
This vulnerability is an unauthenticated flaw in the Open Integration component of Oracle Siebel CRM that allows an attacker with network access to send HTTP requests and read all data exposed by the integration service. The CVSS 3.1 vector indicates AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, meaning that confidential information can be disclosed while integrity and availability remain unchanged.
Affected Systems
Oracle’s Siebel CRM Integration product, versions 25.12 through 26.7, is affected. The vulnerability exists in the Open Integration module, which manages integration endpoints accessible over HTTP.
Risk and Exploitability
The CVSS base score of 7.5 denotes a high‑severity condition, yet the EPSS score of less than 1 % suggests that attacks are not yet widespread or detected. The vulnerability is not listed in the CISA KEV catalog. An attacker does not need credentials; unauthenticated HTTP traffic to the vulnerable integration endpoints is sufficient for exploitation when the service is reachable from the network.
OpenCVE Enrichment