Impact
A flaw in Oracle Siebel CRM Cloud Manager permits an attacker with low privileges and network access over HTTP to gain unauthorized access to critical application data or, in worst cases, all data stored in the Siebel CRM Cloud environment. The weakness effectively bypasses intended access controls and exposes confidential information. Schema-based CWE analysis suggests an Improper Access Control vulnerability.
Affected Systems
Oracle Corporation’s Siebel CRM Cloud Applications are affected, specifically versions 22.3 through 26.5. These releases include the susceptible Siebel Cloud Manager component.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 reflects a moderate-to-high risk level for confidentiality impact, and the vector indicates a network-based attack (AV:N). The EPSS score is below 1 %, suggesting exploitation probability remains low. The vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires an attacker to reach the application over HTTP, craft the appropriate request, and benefit from the flawed access control logic to read protected data. Monitoring for anomalous HTTP traffic and ensuring proper patching are key to mitigating this threat.
OpenCVE Enrichment