Impact
A flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows an attacker who can reach the system over SSH to gain unauthenticated access to all customer data. The vulnerability is an access‑control weakness (CWE‑284) that bypass to read or modify any information stored in the application. The impact is a severe compromise of confidentiality with no direct effect on integrity or availability, as reflected by the CVSS 3.1 score of 8.6.
Affected Systems
Oracle Corporation: Siebel CRM Cloud Applications, specifically the Siebel Cloud Manager component. Versions ranging from 22.3 through 26.7 are affected.|
Risk and Exploitability
The flaw can be exploited by any actor with network reach to the SSH service—no credentials required. The EPSS score of <1% suggests that real‑world exploitation is currently rare, but the high CVSS score and absence from the CISA KEV list indicate that the vulnerability remains a significant threat. Because the scope change is noted, compromise can potentially spread to other foothold is established. An attacker could read, copy, or delete business‑critical data, exposing the organization to financial loss, regulatory penalties, or reputational damage.
OpenCVE Enrichment