Impact
This vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It is a missing authentication flaw (CWE‑306) that allows an unauthenticated attacker with network connectivity to HTTP access to retrieve sensitive data. No authentication is required, and the attack can be performed from an external network, directly compromising confidentiality without affecting integrity or availability.
Affected Systems
Oracle Siebel CRM, specifically the Siebel CRM Cloud Applications product for versions 22.3 through 26.5.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity condition for confidentiality. The low EPSS score of less than 1 % signifies a small likelihood of exploitation at present, though the vulnerability remains publicly known and not yet recorded in CISA's KEV catalog. Attackers would likely target exposed HTTP endpoints of the Siebel Cloud Manager, which are currently reachable without authentication, to obtain critical data. The lack of authentication and only the need for network access reduce the attacker’s effort and prerequisites.
OpenCVE Enrichment