Impact
A vulnerability in Oracle Siebel CRM Cloud Applications’s Siebel Cloud Manager component (CWE-284: Improper Authorization) allows a high‑privileged attacker with network access over HTTP to create, delete, or modify critical data and gain complete access to all data stored in the system. The flaw enables unauthorized manipulation and disclosure of confidential information, compromising the integrity and confidentiality of the application.
Affected Systems
Oracle’s Siebel CRM Cloud Applications, versions 22.3 through 26.6, are affected. Only the Siebel Cloud Manager component is vulnerable; other unrelated software is not impacted.
Risk and Exploitability
The CVSS v3.1 base score of 8.7 indicates high risk, with the attack vector requiring network access, low authentication effort, and high privileges. The scope changes from the vulnerability enable privilege escalation or broader data access. The EPSS score is less than 1%, suggesting exploitation probability is low at present, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless the high confidentiality and integrity impacts warrant immediate action.
OpenCVE Enrichment