CVE-2026-83225
moderateUnauthenticated Denial-of-Service in Oracle Siebel CRM Deployment
CVE-2026-83225 is an easily exploitable flaw in the Server Infrastructure component of Oracle Siebel CRM's Deployment product, affecting supported versions 17.0 through 26.7. An unauthenticated remote attacker who can reach the Siebel server over TCP can trigger the vulnerability without any credentials or user interaction. Successful attacks cause the Siebel CRM Deployment to hang or repeatedly crash, resulting in a complete denial of service; there is no impact on confidentiality or integrity. Any organization running an affected Siebel CRM version with the server infrastructure reachable by untrusted networks is at risk. There is no known public proof of concept, the flaw is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.
What to do: Apply Oracle's Critical Patch Update for Siebel CRM as soon as it covers CVE-2026-83225, or request an interim patch from Oracle Support if you cannot wait for the quarterly cycle. Until patched, restrict TCP access to Siebel server infrastructure ports (including SARM/application server ports) to trusted administration and integration networks via firewalls and ACLs. Monitor Siebel server logs for repeated crashes or hangs consistent with denial-of-service attempts and ensure rapid restart procedures are in place.
| Oracle Siebel CRM (Siebel CRM Deployment, component: Server Infrastructure) | 17.0 - 26.7 (supported versions) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.