Executive brief
A vulnerability exists in the Redwood UI component of Oracle Siebel CRM, a platform used by large organizations to manage customer relationships and business processes. A highly privileged attacker could potentially cause a partial service disruption, though the attack is difficult to execute and requires a legitimate user to perform a specific action. While the direct impact is limited to a partial denial of service, the exploit could potentially affect other integrated systems.
Technical details
This vulnerability affects the Redwood UI component of Oracle Siebel CRM End User versions 24.4 through 26.3. It is classified as difficult to exploit, requiring a high-privileged attacker to have network access via HTTP. A successful exploit requires human interaction from a user other than the attacker and results in a scope change, potentially impacting products beyond the immediate Siebel CRM environment. The primary impact is a partial denial of service (Availability), with no reported impact on confidentiality or integrity. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Siebel CRM End User 24.4-26.3
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.