Impact
Vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications enables a low‑privileged attacker with network access via HTTP to compromise the application. Exploitation can lead to unauthorized access to critical data and allow update, insert, or delete operations, delivering high confidentiality impact and lower integrity impact. The CVSS v3.1 base score of 8.5 reflects these effects and the fact that the vulnerability can change the scope of access.
Affected Systems
Oracle Corporation’s Siebel CRM Cloud Applications are affected. Versions 22.3 through 26.6 contain the flaw. Users running any of these releases should verify their installation version against the product’s baseline documentation.
Risk and Exploitability
The CVSS score of 8.5, combined with an EPSS score of less than 1% and non‑listing in the CISA KEV catalog, indicates that the vulnerability is highly impactful but the likelihood of exploitation remains low, though not negligible. The attack vector is network‑based over HTTP, requires minimal access privileges, and does not rely on user interaction, which makes the risk for internet‑exposed environments significant. Prompt remediation is advisable to prevent potential data exposure or manipulation.
OpenCVE Enrichment