Impact
A flaw was discovered in the Siebel CRM Cloud Applications’ Siebel Cloud Manager component that allows an unauthenticated attacker with HTTPS network access to send specially crafted requests that cause the application to hang or crash. The failure results in a complete denial of service, disabling the application for all users until it is restarted. The vulnerability does not provide confidentiality or integrity gains but fully disrupts availability.
Affected Systems
The flaw affects Oracle Corporation’s Siebel CRM Cloud Applications. Supported versions 22.3 through 26.5 are impacted. All instances of these releases, irrespective of deployment configuration, are vulnerable because the underlying component remains the same.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 reflect a moderate‑to‑high impact on availability with no authentication or user interaction required. The EPSS score of <1% indicates that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote over HTTPS, requiring only network access to exposed endpoints. Because the flaw causes arbitrary process termination, an attacker that succeeds can bring the service down for all users until the application restarts. While exploitation probability is low, the high availability impact warrants prompt attention.
OpenCVE Enrichment