ZeroHour

CVE-2026-83225

moderate

Unauthenticated Denial-of-Service in Oracle Siebel CRM Deployment

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83225 is an easily exploitable flaw in the Server Infrastructure component of Oracle Siebel CRM's Deployment product, affecting supported versions 17.0 through 26.7. An unauthenticated remote attacker who can reach the Siebel server over TCP can trigger the vulnerability without any credentials or user interaction. Successful attacks cause the Siebel CRM Deployment to hang or repeatedly crash, resulting in a complete denial of service; there is no impact on confidentiality or integrity. Any organization running an affected Siebel CRM version with the server infrastructure reachable by untrusted networks is at risk. There is no known public proof of concept, the flaw is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.

What to do: Apply Oracle's Critical Patch Update for Siebel CRM as soon as it covers CVE-2026-83225, or request an interim patch from Oracle Support if you cannot wait for the quarterly cycle. Until patched, restrict TCP access to Siebel server infrastructure ports (including SARM/application server ports) to trusted administration and integration networks via firewalls and ACLs. Monitor Siebel server logs for repeated crashes or hangs consistent with denial-of-service attempts and ensure rapid restart procedures are in place.

Affected
Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure)17.0 - 26.7 (supported versions)
Estimated exposure
moderateLikely low thousands of enterprise Siebel deployments globally, with only hundreds to low thousands of server instances directly internet-exposed (estimate) — Siebel CRM is an enterprise on-premises CRM used by large organizations rather than a mass-market product, and public internet scans typically show only a small fraction of Siebel server infrastructure directly exposed, so total affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.