Executive brief
Oracle Siebel CRM Deployment is a server component used to manage and deploy Siebel customer relationship management systems. An unauthenticated attacker on the network can exploit a vulnerability in the HTTP handler to crash or hang the server repeatedly, causing complete service outages and disrupting business operations that depend on Siebel CRM.
Technical details
This is a denial-of-service vulnerability in the Server Infrastructure component of Siebel CRM Deployment, reachable via HTTP without authentication or user interaction required. The vulnerability allows an unauthenticated network attacker to send specially crafted HTTP requests that trigger a hang or repeatable crash in the affected service. The root cause appears to be improper request handling in the HTTP interface. Successful exploitation results in complete unavailability (DoS) of the Siebel CRM Deployment system. Affected versions are 17.0 through 26.7; patches from Oracle are expected to be available.
Affected products
- Oracle Siebel CRM Deployment 17.0-26.7
Timeline
- 2026-09-15: disclosed