Executive brief
Oracle Siebel CRM Integration is a middleware component that enables data exchange between Siebel CRM and other business systems. An authenticated attacker with network access can exploit a vulnerability in the SOAP interface to read sensitive customer and business data, and to modify or delete records without proper authorization. This could result in data breaches, operational disruption, and loss of data integrity in critical customer relationship management systems.
Technical details
The vulnerability exists in the EAI (Enterprise Application Integration) component of Oracle Siebel CRM Integration and is exploitable through the SOAP protocol. It requires low-privilege network access and authentication, allowing attackers to bypass access controls on data. Successful exploitation enables unauthorized read access to critical data, as well as unauthorized modification, insertion, or deletion of records. The vulnerability affects versions 17.0 through 26.7, and patches or fixes should be available through Oracle's security update channels.
Affected products
- Oracle Siebel CRM Integration 17.0-26.7
Timeline
- 2026-09-15: disclosed