Executive brief
Oracle Siebel CRM Development is a customer relationship management platform used by enterprises to manage customer interactions and business processes. A vulnerability in the scripting integration component allows low-privileged users with network access to crash the system, delete or modify customer data, and read sensitive information. This could disrupt business operations, compromise customer records, and damage customer trust.
Technical details
The vulnerability exists in the Integration - Scripting component of Oracle Siebel CRM Development versions 17.0 through 26.7. It is easily exploitable and requires only low privilege level access and network connectivity via HTTP, with no user interaction needed. An authenticated attacker can exploit this flaw to cause denial of service (system hangs or crashes), perform unauthorized updates, insertions, and deletions of data, and read confidential information accessible within the application. Fixes are expected in Oracle's standard security patch release cycle.
Affected products
- Oracle Siebel CRM Development 17.0-26.7
Timeline
- 2026-09-15: disclosed