ZeroHour

CVE-2026-83197

moderate

Unauthenticated Data Exposure & DoS in Oracle Siebel CRM Financial Services

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83197 is a critical (CVSS 9.1) flaw in the Financial Accounts component of Oracle Siebel Apps - Financial Services, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to read critical data — up to complete access to all data accessible through Siebel Apps - Financial Services — and to cause a hang or frequently repeatable crash, resulting in complete denial of service. Integrity impact is rated as none, so the flaw is primarily a confidentiality and availability risk rather than code execution. No public proof-of-concept exists and the vulnerability is not on the CISA KEV list, so exploitation in the wild is not currently known.

What to do: Check Oracle's latest Critical Patch Update for the Siebel Financial Services fix and apply it to all instances running versions 17.0-26.7. In the interim, restrict HTTP access to Siebel Apps - Financial Services endpoints (network segmentation, VPN, or WAF rules) so they are not reachable by unauthenticated users or the internet. Review logs for anomalous unauthenticated requests against the Financial Accounts component and monitor for unexplained data access or repeated crashes/hangs.

Affected
Oracle Siebel Apps - Financial Services (Oracle Siebel CRM, component: Financial Accounts)17.0-26.7
Estimated exposure
moderate≈ few thousand enterprise deployments, most financial-services organizations (order of magnitude: thousands of organizations) — Siebel CRM is a high-cost enterprise application deployed primarily by large banks and insurers — typically a few thousand organizations globally — and most instances are internal-facing, with public internet scans historically showing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Financial Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Financial Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.