Impact
The vulnerability resides in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. A low‑privileged attacker who can reach the application over HTTP can exploit the flaw to gain full control of the system. The flaw leads to confidentiality, integrity, and availability compromise, allowing an attacker to take over the application entirely.
Affected Systems
The affected systems are Oracle Siebel CRM Cloud Applications versions 22.3 to 26.7. The issue affects all deployments of the Siebel Cloud Manager component within those version ranges.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity with full confidentiality, integrity, and availability impacts. The EPSS score is below 1%, suggesting that widespread exploitation is currently unlikely, and it is not yet cataloged in CISA's KEV. Nevertheless, the low attack‑vector complexity and necessity only for low‑privileged access mean that an attacker with network visibility could potentially exploit the flaw. The vulnerability is easily exploitable, and if successful, results in a complete takeover of the application.
OpenCVE Enrichment