Impact
The vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It permits a low‑privileged local attacker that has logged onto the underlying infrastructure to modify, delete, or insert data, and to read a subset of the application’s data. While the CVSS score of 4.4 reflects limited confidentiality and integrity impact, the ability to alter organisational data can have significant operational repercussions.
Affected Systems
Oracle Siebel CRM Cloud Applications versions 22.3 through 26.5 are affected. The issue specifically involves the Siebel Cloud Manager component, a core part of the stack provided by Oracle Corporation.
Risk and Exploitability
The CVSS base score of 4.4 and an EPSS score below 1% indicate that the vulnerability is not highly generalised and the likelihood of exploitation is low. It is not listed in the CISA KEV catalog. The exploit requires local system access; an attacker would need to be able to log onto the host where the application runs. Because no public exploit is known, the risk remains primarily confined to internal users with insufficient privileges. Nonetheless, the potential for unauthorized data alteration warrants prompt action.
OpenCVE Enrichment