Impact
An attacker who already holds a low‑privilege account can use HTTP requests to bypass the access‑control checks in the Siebel Cloud Manager component, allowing the attacker to create, delete, or alter records in the Siebel CRM Cloud Applications. The flaw compromises confidentiality and integrity, granting the victim the ability to alter or remove critical business data without proper authorization.
Affected Systems
Oracle Siebel CRM Cloud Applications versions 22.3 through 26.6 are impacted. The vulnerability resides in the Siebel Cloud Manager component and affects all users who are able to reach the application over HTTP.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high severity vulnerability that can be exploited over the network with low authentication effort and modest privilege. The EPSS score of less than 1% suggests that observed exploitation is rare, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because it permits unauthorized data modification through an access‑control bypass (CWE‑284), the potential impact on essential business information is significant.
OpenCVE Enrichment