Executive brief
A vulnerability exists in the Siebel Server Sync for Exchange component of Oracle Siebel CRM, which synchronizes data between the CRM and Microsoft Exchange. An attacker could potentially modify, add, or delete certain data within the CRM system without needing a password. While the risk to data integrity is present, the vulnerability is considered difficult to exploit and does not allow for the theft of sensitive information or the complete shutdown of the service.
Technical details
This vulnerability affects the Siebel Server Sync for Exchange component within Oracle Siebel CRM Integration versions 17.0 through 26.5. It is an unauthenticated vulnerability reachable via HTTP over the network. The attack complexity is rated as High, suggesting that successful exploitation requires specific conditions or significant effort beyond simple network reachability. If successfully exploited, an attacker can gain unauthorized update, insert, or delete access to a subset of data accessible to the Siebel CRM Integration. The impact is limited to integrity, with no reported impact on confidentiality or availability. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Siebel CRM Integration 17.0-26.5
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60357 was published to the NVD.