Impact
A flaw in Siebel CRM Cloud Applications permits an unauthenticated attacker with physical network access to the hardware that hosts the application to create, modify, or delete data, as well as to read any data stored in the system violations without affecting availability.
Affected Systems
The issue affects Oracle Siebel CRM Cloud Applications versions 22.3 through 26.7. Users of these versions should check which release they are running and plan an upgrade or patch. No other products or versions are specifically noted in the report.
Risk and Exploitability
The base CVSS score of 8.1 highlights high impact, while the EPSS score of less than 1% indicates that the vulnerability is not widely exploited as of now and it is not listed in the CISA KEV catalog. The vulnerability is exploitable from the adjacent network, meaning that anyone with physical or local network connectivity to the machine can trigger the flaw without authentication. The risk is therefore significant for environments that do not isolate the Siebel environment from other local hosts.
OpenCVE Enrichment