Impact
A flaw in the Siebel Cloud Manager component of Oracle’s Siebel CRM Cloud Applications allows an unauthenticated attacker who can reach the system over the network to gain unauthorized read access to the application data. The vulnerability, identified as CWE‑306, is caused by inadequate authentication controls that permit remote exploitation via standard HTTP traffic. Because the issue can be triggered without credentials, the confidentiality of data stored in the CRM is directly threatened.
Affected Systems
Oracle Corporation’s Siebel CRM Cloud Applications, specifically the Siebel Cloud Manager component, is affected for supported releases 22.3 through 26.5. Systems deploying these versions should confirm the installation of the component and the exact patch level.
Risk and Exploitability
The attack vector is network‑based using normal HTTP requests; authentication is not required. The EPSS score is below 1 %, indicating that broad exploitation is presently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Still, the combination of remote access, lack of authentication, and high confidentiality impact gives the CVSS score of 7.5 a significant risk level to data confidentiality if the flaw were to be leveraged.
OpenCVE Enrichment