Impact
This vulnerability is present in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. The underlying weakness is a CWE‑284 (Improper Access Control). It permits a low‑privileged attacker who can reach the system over HTTP to create, delete or modify data, read sensitive information, and cause the application to hang or crash repeatedly, disrupting availability. The weakness results in lost confidentiality for the read function and substantial integrity and availability damage for the entire application.
Affected Systems
The affected vendor is Oracle Corporation and the product is Siebel CRM Cloud Applications. Versions 22.3 through 26.6 are considered vulnerable. Users running these releases should verify if they are in the affected range.
Risk and Exploitability
The CVSS base score of 8.3 indicates high severity with high impact to integrity and availability. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote over the network via HTTP, requiring only low privilege to exploit. An attacker could exploit the flaw to alter or delete critical data and potentially trigger denial‑of-service conditions that affect all users of the application.
OpenCVE Enrichment