Impact
The vulnerability exists in the Cloud Gateway component of Oracle Siebel CRM Deployment. An attacker who has low‑level privileges and can reach the system over HTTP can use the flaw to add, remove, or alter critical data, or to gain full read access to all data available through the deployment. This results in confidentiality and integrity loss for sensitive business information. The weakness is an improper access control flaw (CWE‑284).
Affected Systems
Oracle Corporation’s Siebel CRM Deployment product, targeting the Cloud Gateway, is impacted for versions 17.0 through 26.7. Users running any of these releases are vulnerable unless they apply the patch or update.
Risk and Exploitability
The CVSS v3.1 base score is 6.8, reflecting moderate severity with high confidentiality and integrity impacts. The EPSS score indicates an exploitation probability of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog. The flaw is reachable over the network via HTTP, requires only low privileges, and does not require elevated permissions or authentication beyond local or remote user status. Thus, while the potential impact is significant, the likelihood of active exploitation remains low as of the latest data.
OpenCVE Enrichment