Impact
The vulnerability in Siebel CRM Cloud Applications originates from the Siebel Cloud Manager component and permits an unauthenticated attacker with network access to perform unauthorized operations without authentication. The flaw enables the attacker to read critical data, modify or delete records, and even make the application partially unavailable. These capabilities correspond to a high confidentiality impact, low integrity impact, and a low availability impact, as captured by a CVSS score of 7.0.
Affected Systems
Affected systems are Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5. All organizations running any of these versions are exposed unless a compatible patch has been installed.
Risk and Exploitability
The risk is moderate to high given the CVSS base score but the EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, which indicates low current exploit activity. Based on the description, it is inferred that the likely attack vector is network access via HTTP to the Siebel Cloud Manager. Attackers would need only access to the HTTP interface of the Siebel Cloud Manager, making the attack vector local network or internet if the interface is exposed. Based on the description, it is inferred that the vulnerability represents an authentication bypass, as no authentication or privilege is required, leading to privilege escalation within the application.
OpenCVE Enrichment