CVE-2026-60709
MEDIUM
4.2
CVSS 3.1
Metadata
Severity & Metrics
4.2
MEDIUM CVSS 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Oracle Corporation | Siebel CRM Cloud Applications | — | 22.3 ≤ 26.5 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 4.2 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
References (1)
- Oracle Advisory https://www.oracle.com/security-alerts/cpujul2026.html