Impact
Oracle Siebel CRM Cloud Applications contains an unauthorized access flaw in the Siebel Cloud Manager module that allows an unauthenticated attacker to send HTTP requests and read or modify application data. The vulnerability bypasses authorization checks, providing the ability to insert, update, or delete critical customer information and resulting in confidentiality and integrity compromise. This weakness is a classic example of improper authorization (CWE-284).
Affected Systems
Affected systems are Oracle Siebel CRM Cloud Applications, versions 22.3 through 26.7, in deployments that include the Siebel Cloud Manager component. No other vendors or product lines are listed as affected.
Risk and Exploitability
The flaw is reachable over HTTP without authentication, giving an external attacker a simple attack vector. The CVSS v3.1 base score of 8.2 reflects significant confidentiality impact and moderate integrity impact. The EPSS score of less than 1% indicates a low current probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment