Executive brief
Oracle Siebel CRM Deployment is enterprise software used to manage customer relationships and sales operations. A SQL injection vulnerability in the Server Infrastructure component allows a low-privileged network attacker to gain complete control of the system, compromising the confidentiality, integrity, and availability of all customer data and business operations running on the platform.
Technical details
A SQL injection vulnerability exists in the Oracle Siebel CRM Deployment Server Infrastructure component affecting versions 17.0 through 26.7. The vulnerability is easily exploitable over the network and requires only low-level privileges and no user interaction. An attacker with network access can craft malicious SQL queries to achieve complete compromise of the system, including unauthorized data access, data modification, and service disruption. The CVSS 3.1 score of 8.8 reflects the high impact on confidentiality, integrity, and availability. Patch status and fix availability should be verified through Oracle's security updates.
Affected products
- Oracle Siebel CRM Deployment 17.0-26.7
Timeline
- 2026-09-15: disclosed