Impact
A flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows a high‑privileged attacker who can log on to the infrastructure that hosts the application to create, delete, or modify critical data, or otherwise gain full access to all data stored in the system. The misconfigured access control (CWE‑284) can bypass normal authorization safeguards, leading to confidentiality and integrity violations for data managed by the application and for any integrated products that share the scope.
Affected Systems
Oracle Siebel CRM Cloud Applications, specifically versions 22.3 through 26.7 of the Siebel Cloud Manager component, as identified in Oracle’s security advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.9 denotes high severity with substantial confidentiality and integrity impacts. The EPSS score of <1% indicates a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local system access: an attacker must be able to log on to the infrastructure where Siebel CRM Cloud Applications runs. Once this condition is met, the attacker can alter permissions or data records, enabling unauthorized data manipulation or disclosure.
OpenCVE Enrichment