Impact
This vulnerability in Oracle Siebel CRM Cloud Applications, specifically the Siebel Cloud Manager component, allows a user with local credentials who hosts the application to compromise the application and read or write all data handled by the service. The flaw is classified as a high confidentiality compromise, with no impact on integrity or availability, and is rated with a CVSS 3.1 base score of 6.5.
Affected Systems
Affected systems are Siebel CRM Cloud Applications, including the Siebel Cloud Manager, across all supported releases from version 22.3 through 26.5. Versions 26.6 and later contain the fix and are recommended for secure operation.
Risk and Exploitability
The vulnerability's CVSS score of 6.5 suggests moderate severity, while an EPSS score of less than 1 % indicates that exploitation is currently low probability. However, the attack has a local prerequisite; an attacker must already have logged into the application’s underlying infrastructure, a condition that is often within reach for low‑privileged staff or compromised accounts. Once the local compromise is achieved, the change in scope allows the attacker to potentially affect additional applications running in the same environment. The vulnerability is not listed in the CISA KEV catalog, but its potential to broaden access beyond the target application warrants careful monitoring and quick remediation.
OpenCVE Enrichment