Impact
The vulnerability in Siebel CRM Cloud Applications allows an attacker to create, delete, or modify critical data without authentication, leading to confidentiality and integrity losses. It is an access control flaw that lets an unauthorized party alter or delete data that should be protected.
Affected Systems
Oracle Siebel CRM Cloud Applications version 22.3 through 26.6 are affected. The product is Oracle's Siebel CRM Cloud Manager component. The affected deployments run on hardware where the application is executed.
Risk and Exploitability
The CVSS 3.1 score of 8.1 indicates high severity. The EPSS score of <1% indicates a very low probability of exploitation. The attack requires physical access to the communication segment attached to the hardware, so the scope is limited to environments where such access is possible. There is no publicly known exploit at the moment, and the vulnerability is not listed in CISA KEV. Nevertheless, once a physical attacker gains access, they can bypass all authentication controls and gain full access to data.
OpenCVE Enrichment