Impact
The flaw is an access control weakness (CWE-284) in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It lets an attacker who has low privileges and physical access to the hardware’s network segment obtain unauthorized read access to critical data, and, if employed successfully, update, insert, or delete data and trigger a partial denial of service. The vulnerability directly compromises confidentiality, with lower impacts on integrity and availability.
Affected Systems
Oracle Siebel CRM Cloud Applications versions 22.3 through 26.7 are affected. Any user or system that can reach the physical communication segment attached to the host running Siebel CRM Cloud Applications can exploit the flaw.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 shows high severity, with confidentiality high, integrity low, and availability low. The EPSS score is below 1%, indicating a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, the attacker only needs low privileges and local network access, and the scope expansion can affect additional products linked to the application, making the attack likely in environments where the physical network segment is not isolated.
OpenCVE Enrichment