Executive brief
Oracle Siebel CRM Deployment is a customer relationship management platform used by enterprises to manage customer interactions and business processes. A SQL injection vulnerability in the Migration component allows authenticated users with network access to execute arbitrary SQL commands, potentially compromising the entire system's confidentiality, integrity, and availability.
Technical details
A SQL injection vulnerability exists in the Migration component of Oracle Siebel CRM Deployment affecting versions 17.0 through 26.7. The vulnerability allows a low-privileged attacker with network access to inject arbitrary SQL commands via the Migration functionality. Authentication is required to exploit this vulnerability, but no user interaction is needed once the attacker gains access. Successful exploitation results in complete compromise of the Siebel CRM Deployment instance, including unauthorized access to sensitive data, modification of business data, and potential denial of service. Patch status is not explicitly confirmed in the advisory summary.
Affected products
- Oracle Siebel CRM Deployment 17.0-26.7
Timeline
- 2026-09-15: disclosed