Impact
Oracle Siebel CRM Cloud Applications is vulnerable to an easily exploitable flaw in the Siebel Cloud Manager component that permits a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can lead to full takeover of the system, affecting confidentiality, integrity and availability.
Affected Systems
Oracle Siebel CRM Cloud Applications, versions 22.3 through 26.6 are affected.
Risk and Exploitability
The Base CVSS score of 9.9 indicates a critical severity. The attack vector is network‑based, requires low privilege, and the vulnerability can change scope, suggesting a privilege escalation path. The EPSS score is <1%, indicating a very low exploitation probability. Despite the low EPSS, the confirmed high CVSS score and the ability to fully compromise the system warrant immediate attention. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment