Executive brief
A vulnerability exists in the Database Upgrade component of Oracle Siebel CRM Deployment. An attacker with low-level access to the underlying server infrastructure can exploit this flaw to take full control of the Siebel CRM Deployment system. This could lead to the unauthorized access, modification, or deletion of sensitive customer relationship management data and disruption of business operations.
Technical details
An improper access control vulnerability (CWE-284) exists in the Database Upgrade component of Oracle Siebel CRM Deployment. The flaw is easily exploitable by a low-privileged attacker who has local logon access to the infrastructure where the software executes. Successful exploitation allows the attacker to compromise the confidentiality, integrity, and availability of the deployment, effectively resulting in a complete system takeover. The vulnerability affects supported versions 17.0 through 26.5. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle Siebel CRM Deployment 17.0-26.5
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory