Executive brief
Oracle Siebel CRM is a customer relationship management platform used by enterprises to manage sales, customer service, and business operations. A vulnerability in the Reports component allows unauthenticated attackers with network access to read sensitive customer data and business-critical information without authorization, potentially exposing customer records, transaction history, and other confidential business data.
Technical details
This is an information disclosure vulnerability in the Siebel CRM Reports component affecting versions 17.0 through 26.7. The vulnerability can be exploited by an unauthenticated attacker over the network via HTTP without requiring user interaction or special conditions. The flaw allows attackers to bypass authentication controls and gain unauthorized access to critical data stored within Siebel CRM. The attack has a low complexity barrier and yields high confidentiality impact (exposure of confidential data). No integrity or availability impacts are reported.
Affected products
- Oracle Siebel CRM 17.0-26.7
Timeline
- 2026-09-15: disclosed