Executive brief
Oracle Siebel CRM Deployment is a customer relationship management system used by enterprises to manage business operations and customer interactions. A remote code execution vulnerability in the Server Infrastructure component allows a low-privileged attacker with network access to take over the entire Siebel CRM Deployment system, gaining complete control over customer data, business processes, and system availability.
Technical details
This vulnerability in Oracle Siebel CRM Deployment's Server Infrastructure component is easily exploitable by a low-privileged attacker with network access via HTTP. The attack requires authentication (low privilege credentials) but no user interaction. Successful exploitation results in complete compromise of the affected system with high impact to confidentiality, integrity, and availability (CVSS 8.8). The vulnerability allows an attacker to execute arbitrary code and achieve system takeover. Affected versions range from 17.0 through 26.7. No patch information is currently available in the advisory.
Affected products
- Oracle Siebel CRM Deployment 17.0 to 26.7
Timeline
- 2026-09-15: disclosed