Executive brief
Siebel CRM Deployment is an enterprise customer relationship management system used to manage business operations and customer data. A vulnerability in the Server Infrastructure component allows an attacker with network access to the CRM server's communication segment and low-level privileges to read sensitive customer data and cause service outages, potentially disrupting critical business operations and exposing confidential customer information.
Technical details
This is a low-complexity, easily exploitable vulnerability in the Siebel CRM Deployment Server Infrastructure component affecting versions 17.0 through 26.7. The vulnerability requires adjacent network access (physical communication segment) and low-level user privileges to exploit. Successful exploitation enables unauthorized access to sensitive data (high confidentiality impact) and the ability to trigger denial-of-service conditions through application hangs or crashes (high availability impact). Patch availability is not specified in the advisory; Oracle security alerts should be consulted for remediation guidance.
Affected products
- Oracle Siebel CRM Deployment 17.0-26.7
Timeline
- 2026-09-15: disclosed