Impact
The vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. An unauthenticated attacker who can reach the application over the network via HTTP can exploit it. Successful exploitation can grant unauthorized access to critical data stored in the CRM, potentially exposing all data available within the application. The flaw is classified with a CVSS 3.1 base score of 7.5, highlighting significant confidentiality impact while integrity and availability remain unaffected.
Affected Systems
Oracle Siebel CRM Cloud Applications, specifically versions 22.3 through 26.7, are affected. Any deployment of these versions with the Siebel Cloud Manager component exposed over HTTP is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the EPSS score of less than 1% suggests that exploitation is not yet widespread but could occur due to the ease of the attack. Because the vulnerability requires no authentication and is reachable over standard HTTP, it can be leveraged by attackers with simple network access, potentially compromising the confidentiality of all data within the affected applications. The flaw is not yet listed in CISA KEV, so no known exploitation campaigns are confirmed, but the risk remains significant, especially for publicly exposed services.
OpenCVE Enrichment