Executive brief
Oracle Siebel CRM Deployment is a business application used to manage customer relationships and sales operations. A vulnerability in the Siebel Remote component allows a low-privileged attacker with network access to completely take over the system, gaining full control over customer data, business operations, and system integrity. This could lead to data theft, operational disruption, and reputational damage.
Technical details
This is a difficult-to-exploit vulnerability in the Siebel Remote component of Siebel CRM Deployment affecting versions 17.0 through 26.7. The flaw requires network access via HTTP and low-level user privileges, but does not require user interaction to exploit. A successful attack results in complete compromise of the affected system with full confidentiality, integrity, and availability impact—enabling the attacker to read, modify, and delete data, as well as disrupt service availability. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting its high severity and the significant business impact.
Affected products
- Oracle Siebel CRM Deployment 17.0–26.7
Timeline
- 2026-09-15: disclosed