ZeroHour

CVE-2026-83155

moderate

Adjacent-Network Data Access and DoS in Oracle Siebel CRM Server Infrastructure

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable flaw in the Server Infrastructure component of the Siebel CRM Deployment product allows a low-privileged attacker with a foothold on the same physical network segment as the Siebel server to compromise the deployment. A successful attack gives unauthorized access to critical data — up to complete access to all data reachable by the Siebel CRM Deployment — and the ability to hang or repeatedly crash the service, producing a complete denial of service; integrity is not impacted. All supported Siebel CRM versions from 17.0 through 26.7 are affected. Because exploitation requires both an adjacent network position and low-privileged credentials, the practical risk sits on internal corporate networks rather than the public internet, and no public proof of concept or known in-the-wild exploitation has been reported. Oracle addressed the issue through its Critical Patch Update process.

What to do: Apply the Oracle Critical Patch Update that remediates this issue and move to a release beyond the affected 17.0–26.7 range. Restrict which hosts, VLANs, and low-privileged accounts can reach the network segments attached to Siebel CRM servers. Monitor Siebel server logs for anomalous data-access patterns and recurring crashes or hangs that could indicate exploitation attempts.

Affected
Oracle Siebel CRM (Siebel CRM Deployment — Server Infrastructure component)17.0-26.7
Estimated exposure
moderatelikely a few thousand enterprise deployments (order of 10³ sites), unknown precisely — Siebel CRM is an on-premises enterprise product with no public install counts; its remaining installed base consists mainly of large organizations (financial services, telecom, government), and practically exploitable exposure is further…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).

Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.