Impact
The vulnerability is located in the Siebel Cloud Manager component of Oracle’s Siebel CRM Cloud Applications and is present in versions 22.3 through 26.7. A low‑privileged attacker who has network connectivity via HTTP can exploit the flaw to bypass normal access controls, allowing the attacker to insert, update, or delete records and to read portions of the data that should remain confidential. This vulnerability results in a direct compromise of data integrity and confidentiality for the affected system.
Affected Systems
Oracle Corporation’s Siebel CRM Cloud Applications 22.3 – 26.7 are affected. The flaw may also impact additional products when the scope changes, as noted in the advisory, but the primary target is the cloud application itself.
Risk and Exploitability
The CVSS v3.1 base score is 6.4 with the attack vector described as network, access complexity low, and the required privileges low, yet no user interaction is needed. The EPSS score of <1% indicates a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw involves a scope change, a successful exploit can potentially affect other components or related services, increasing the overall impact. The moderate severity combined with low exploit prevalence suggests that monitoring and timely patching are advised.
OpenCVE Enrichment