Executive brief
Oracle Siebel CRM End User is a customer relationship management system used by enterprises to manage customer interactions and data. A cross-site scripting vulnerability in the Open UI component allows a low-privileged attacker to trick users into performing actions that could lead to unauthorized access, modification, or deletion of critical customer data, with potential impact extending beyond Siebel to other connected systems.
Technical details
This is a cross-site scripting (XSS) vulnerability in the Open UI component of Oracle Siebel CRM End User. The vulnerability requires network access via HTTP and can be exploited by a low-privileged attacker, but requires user interaction (specifically human interaction from someone other than the attacker) to succeed. The attack has a high complexity (AC:H) rating. Successful exploitation enables unauthorized access to, creation, deletion, or modification of critical data accessible through Siebel CRM End User, and may impact other connected products due to scope change. Patches are available for supported versions 17.0 through 26.7.
Affected products
- Oracle Siebel CRM End User 17.0 through 26.7
Timeline
- 2026-09-15: disclosed