Junglewise Threat Intelligence

CVE-2026-83225: Oracle Siebel CRM Deployment denial of service in Server Infrastructure

CVE-2026-83225 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

Oracle Siebel CRM Deployment is a customer relationship management platform used by enterprises to manage client interactions and business processes. An unauthenticated attacker on the network can crash or hang the Siebel server repeatedly, causing a complete denial of service that disrupts all customer-facing and internal CRM operations until the service is manually restarted.

Technical details

This is a denial-of-service vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment. The vulnerability is easily exploitable and requires no authentication, allowing an unauthenticated attacker with network access to send a crafted TCP payload that triggers a crash or hang condition. The root cause and specific attack mechanism are not detailed in the available advisory. Successful exploitation results in complete unavailability (hang or crash) of the Siebel CRM Deployment service. The vulnerability affects versions 17.0 through 26.7, and fixes or patches should be available from Oracle.

Affected products

  • Oracle Siebel CRM Deployment 17.0–26.7

Timeline

  • 2026-09-15: disclosed

References

Related threats