Impact
The vulnerability allows a high‑privileged attacker who can log on to the infrastructure that runs Siebel CRM Cloud Applications to create, delete, or modify critical data. An attacker could gain full access to any data stored in the application, bypassing normal authorization controls and potentially exposing confidential information. The weakness is an improper access control flaw that compromises confidentiality and integrity for the entire application.
Affected Systems
Oracle Siebel CRM Cloud Applications, specifically versions 22.3 through 26.7 of the Siebel Cloud Manager component.
Risk and Exploitability
The CVSS 3.1 base score of 7.9 indicates high severity with significant confidentiality and integrity impact. The EPSS score of less than 1% suggests limited exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires local system access; the attacker must be able to log on to the infrastructure where Siebel CRM Cloud Applications runs. Availability is not impacted. The flaw can be exploited by modifying application permissions or data records, leading to unauthorized data manipulation or disclosure.
OpenCVE Enrichment