{
  "cve": "CVE-2026-83182",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "[17.0,26.7]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "product": "siebel_crm_development",
        "vendor": "oracle"
      }
    ],
    "created": "2026-09-16T03:15:06.655330+00:00",
    "title": "SQL Vulnerability in Siebel CRM Development Allows Low-Privileged Application Takeover",
    "updated": "2026-09-20T10:00:09.753849+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$siebel_crm_development"
    ]
  },
  "epss": {
    "score": 0.00323
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T20:04:13.404000+00:00",
    "description": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.5,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/83xxx/CVE-2026-83182.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T15:15:41.379000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$siebel_crm_development"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [],
    "created": "2026-09-15T20:18:29.357000+00:00",
    "description": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.5,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-83182.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T16:18:07.880000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-284"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-15T20:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$siebel_crm_development"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$siebel_crm_development"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspusep2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 7.5,
                  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "c2f379bc-d65e-48f0-9d24-424e669fe62c"
      },
      {
        "created": "2026-09-17T02:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "SQL Injection Leading to Full Application Takeover in Oracle Siebel CRM Development",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-89"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "5097c539-4307-4926-b4ce-1c6ae056409d"
      },
      {
        "created": "2026-09-17T16:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-284"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "8132382c-ee78-4b53-93e9-f20024c506c0"
      },
      {
        "created": "2026-09-18T21:30:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "SQL Injection Leading to Full Application Takeover in Oracle Siebel CRM Development"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-89"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "ae3a5c7b-eace-4bb9-9f59-8f6ab97c98d5"
      },
      {
        "created": "2026-09-20T10:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "SQL Vulnerability in Siebel CRM Development Allows Low-Privileged Application Takeover",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "00e84c87-938e-45af-a4d4-0a198c9be16a"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:siebel_crm_development:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2026-09-15T20:04:13.404000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 7.5,
          "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00323
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "SQL Vulnerability in Siebel CRM Development Allows Low-Privileged Application Takeover",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-09-20T10:00:09.753849+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$siebel_crm_development"
      ],
      "providers": [
        "mitre",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-284"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-15T20:04:13.404000+00:00",
    "description": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-17T14:58:27.772000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/83xxx/CVE-2026-83182.json",
    "weaknesses": [
      "CWE-284"
    ]
  }
}