Impact
The vulnerability resides in Siebel CRM Cloud Applications, specifically the Siebel Cloud Manager component. An unauthenticated attacker with network access via HTTP can exploit the flaw, potentially gaining unauthorized access to critical application data or even complete access to all data accessible within the platform. Successful exploitation also allows the attacker to perform insert, update, or delete operations on data and to cause partial denial of service. The weakness is an improper access control/authorization flaw that permits unauthorized manipulation of sensitive resources, causing confidentiality, integrity, and availability impacts at a broad scope as indicated by the scope change in the CVSS vector.
Affected Systems
The product affected is Oracle Siebel CRM Cloud Applications, version range 22.3 through 26.6. These cloud deployments expose the Siebel Cloud Manager component over HTTP to the network.
Risk and Exploitability
The CVSS v3.1 score of 9.9 indicates critical severity with high impacts on confidentiality, integrity, and availability. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no credentials. The EPSS score of <1% indicates a very low probability of exploitation, yet the low likelihood does not reduce the urgency because the critical severity and extended scope remain. The vulnerability is not listed in the CISA KEV catalog, suggesting no active exploitation is known, but the risk should still be addressed promptly. Attackers could thus access, modify or delete data and cause partial denial of service.
OpenCVE Enrichment