Executive brief
A vulnerability exists in the Application Interface component of Oracle Siebel CRM, a platform used by large organizations to manage customer relationships and business processes. An attacker with low-level access could potentially view a limited amount of sensitive data, though the attack is difficult to perform and requires a legitimate user to take a specific action. This issue primarily impacts the confidentiality of information stored within the CRM system.
Technical details
This vulnerability affects the Application Interface component of Oracle Siebel CRM Deployment versions 17.0 through 26.4. It is classified as a low-severity issue with a CVSS score of 2.6, primarily due to high attack complexity and the requirement for user interaction. An attacker with low-privileged network access via HTTP can exploit this flaw to achieve unauthorized read access to a subset of data. The vulnerability is characterized by a 'High' Attack Complexity (AC:H) and requires 'Required' User Interaction (UI:R), limiting the scope of potential impact to confidentiality (C:L). Patch information is typically found in the Oracle Critical Patch Update (CPU) advisories.
Affected products
- Oracle Corporation Siebel CRM Deployment 17.0-26.4
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.
- 2026-07-21: advisory