Executive brief
Oracle Siebel CRM Deployment is a customer relationship management platform used to manage critical business data and customer interactions. An unauthenticated attacker can exploit a vulnerability in the Server Infrastructure component via HTTP to read, modify, or delete sensitive customer and business data without any authentication or user interaction.
Technical details
This is an unauthenticated remote code execution or data access vulnerability in the Server Infrastructure component of Siebel CRM Deployment. The vulnerability is easily exploitable and requires only network-level HTTP access with no authentication or user interaction required. Successful exploitation allows an attacker to achieve both confidentiality and integrity impacts, including unauthorized creation, deletion, or modification of critical data within Siebel CRM Deployment, as well as complete read access to all accessible data. The vulnerability affects versions 17.0 through 26.7.
Affected products
- Oracle Siebel CRM Deployment 17.0 to 26.7
Timeline
- 2026-09-15: disclosed