Impact
The vulnerability is located in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It allows an attacker who has network connectivity to the application over HTTP to authenticate implicitly and gain full control of the system. Because no user credentials are required, the flaw enables a remote takeover that can leak confidential information, alter data, and disrupt services. The weakness maps to improper access control.
Affected Systems
The affected product is Oracle Siebel CRM Cloud Applications, versions 22.3 through 26.6 inclusive. These releases are widely used by enterprises for customer relationship management.
Risk and Exploitability
The CVSS v3.1 base score is 9.8, indicating critical severity. The exploit does not require authentication or user interaction, uses the network attack vector, and delivers complete compromise of confidentiality, integrity, and availability. The EPSS score is < 1%, so the probability of exploitation is low but nonzero, and the vulnerability is not listed in CISA’s KEV catalog. The flaw can be executed by any unauthenticated actor with HTTP access to the Siebel CRM Cloud Applications endpoint.
OpenCVE Enrichment