Impact
A flaw in the Siebel Cloud Manager component of Oracle’s Siebel CRM Cloud Applications allows a remote attacker with low privileges but network access via HTTP to manipulate the system and potentially gain full control. The vulnerability compromises confidentiality, integrity, and availability, and the CVSS score of 9.9 reflects a critical exploitation scenario.
Affected Systems
Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5 are affected. The attack may also impact additional products because the vulnerability changes the scope of privileges granted to the attacker.
Risk and Exploitability
The CVSS score of 9.9 indicates maximum severity, but the EPSS score is listed as < 1%, suggesting that, as of this assessment, the probability of exploitation is extremely low and the vulnerability is not currently included in the CISA KEV catalog. The likely attack vector is over the network using HTTP and requires only low‑privileged authentication to succeed.
OpenCVE Enrichment