Impact
The vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications and permits an unauthenticated attacker with access to the physical communication segment to modify, insert, or delete data, as well as read a subset of data the application exposes. The weakness reflects an improper access control flaw that compromises data confidentiality and integrity, allowing the attacker to tamper with stored information without authorization.
Affected Systems
Oracle Corporation’s Siebel CRM Cloud Applications, versions 22.3 through 26.5, are impacted. These versions contain the vulnerable Siebel Cloud Manager that fails to enforce proper authorization checks for data operations exposed over the local communication segment.
Risk and Exploitability
The CVSS v3.1 base score of 4.2 indicates moderate confidentiality and integrity impacts with local access as the attack vector, high attack complexity, no privileges or user interaction required, and unchanged scope. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be physically present to reach the hardware’s communication segment; no network or remote access is necessary. Upon execution, the attacker can perform unauthorized data modifications or reads, potentially compromising sensitive customer information stored within the application.
OpenCVE Enrichment