Executive brief
Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage customer interactions and business operations. A vulnerability in the Siebel CRM Deployment Server Infrastructure allows a low-privileged attacker with network access to gain complete control of the system, potentially compromising customer data, business operations, and system integrity.
Technical details
A network-accessible vulnerability in Oracle Siebel CRM Deployment Server Infrastructure allows low-privileged attackers to compromise the system via HTTP without additional user interaction. The vulnerability has a CVSS 3.1 score of 8.8, indicating high impact to confidentiality, integrity, and availability. The vulnerability affects Siebel CRM versions 17.0 through 26.7. The exact root cause and attack mechanism are not detailed in available sources, but the combination of network accessibility, low privilege requirements, and complete system compromise potential suggests an authentication or authorization weakness. No public exploitation has been reported as of the publication date.
Affected products
- Oracle Siebel CRM 17.0–26.7
Timeline
- 2026-09-15: disclosed