Impact
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications enables a local attacker who has already logged onto the underlying infrastructure to compromise the application. The flaw allows the attacker to take full control, resulting in potential compromise of confidentiality, integrity, and availability of the data handled by the application. This is an access control weakness, classified as CWE-284.
Affected Systems
The affected product is Oracle Siebel CRM Cloud Applications, versions 22.3 through 26.6. No other vendors or product lines are listed as impacted.
Risk and Exploitability
Because any user who can log onto the host can exploit it, the risk is significant, especially in shared or privileged environments. The CVSS 3.1 base score of 7.8 indicates high impact on confidentiality, integrity, and availability. The EPSS score is less than 1% and it is not listed in the CISA KEV catalog. Nevertheless, the high severity suggests that exploitation could result in complete takeover of the application if an attacker gains access to the underlying system.
OpenCVE Enrichment