Impact
The vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It enables a low‑privileged attacker who can reach the service over HTTP to fully compromise the application, resulting in loss of confidentiality, integrity, and availability. The weakness is an improper access control that permits exploitation without elevated permissions.
Affected Systems
Vendor: Oracle Corporation. Product: Siebel CRM Cloud Applications (Siebel Cloud Manager). Affected versions are 22.3 through 26.6, inclusive. No other version information is provided.
Risk and Exploitability
The CVSS 3.1 base score is 9.9, indicating critical risk. EPSS score is 0.00447, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers require network access over HTTP and only low privileges to exploit the flaw. Successful exploitation leads to takeover of the CRM instance and may affect connected products due to scope change.
OpenCVE Enrichment