Executive brief
Oracle Siebel CRM Integration is a system used to connect CRM data with other enterprise applications. A vulnerability in the EAI (Enterprise Application Integration) component allows a low-privileged attacker with network access to take over the entire Siebel CRM Integration system, potentially exposing or altering critical customer and business data.
Technical details
This is a network-accessible vulnerability in the EAI component of Oracle Siebel CRM Integration (versions 17.0–26.7) that allows low-privileged authenticated attackers to compromise the system. The vulnerability has a CVSS score of 7.5 with high impact across confidentiality, integrity, and availability. Attack requires network access via HTTP and authentication but is considered difficult to exploit. Successful exploitation results in complete system compromise, allowing takeover of the Siebel CRM Integration instance. Patch status and detailed remediation guidance should be obtained from Oracle's security bulletins.
Affected products
- Oracle Siebel CRM Integration 17.0–26.7
Timeline
- 2026-09-15: disclosed