Impact
A flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications enables an unauthenticated attacker to issue HTTP requests that bypass authorization checks. This allows the attacker to read or alter sensitive customer data, with the potential to insert, update, or delete records, thereby compromising the confidentiality and integrity of the application’s data.
Affected Systems
Oracle Siebel CRM Cloud Applications versions 22.3 through 26.7 are affected, provided the Siebel Cloud Manager component is deployed. The issue is exposed over HTTP, and no authentication or authorization is required to exploit it.
Risk and Exploitability
The vulnerability scores a CVSS v3.1 base score of 8.2, indicating high risk to confidentiality and moderate impact on integrity. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is reachable via plain HTTP without any authentication, an external attacker only needs network access to the application to exploit the issue.
OpenCVE Enrichment