Impact
The Siebel CRM Cloud Applications product contains a vulnerability in the Siebel Cloud Manager component that allows attackers with low‑privileged credentials and network access via HTTP to take full control of the system. Successful exploitation can compromise confidential data, alter or delete records, and disrupt service, resulting in total loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Siebel CRM Cloud Applications versions 22.3 through 26.6 are affected. The flaw is located in the Siebel Cloud Manager component of these releases.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 indicates high severity. EPSS score is 0.00447, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is sending crafted HTTP requests to the Siebel Cloud Manager endpoint; the low privilege requirement suggests that attackers need only basic credentials or none at all, and the vulnerability is described as easily exploitable.
OpenCVE Enrichment