Impact
A flaw in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications permits a low‑privileged attacker with network access via HTTP to create, delete or modify critical data, and to obtain full access to all data accessible through the application. This vulnerability is a CWE‑284 (Improper Access Control) and results in significant confidentiality and integrity impacts, as unauthorized manipulation of application data and sensitive information is possible.
Affected Systems
Oracle Corporation’s Siebel CRM Cloud Applications are affected, specifically versions 22.3 through 26.7. The weakness may also have a broader impact on other products due to the scope change noted in the advisory.
Risk and Exploitability
The CVSS base score of 8.2 indicates high severity, yet the EPSS score of less than 1% reflects a low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via network HTTP connections from an attacker with low pre‑existing privileges, exploiting insufficient authorization controls to gain unauthorized data creation, deletion, or modification privileges.
OpenCVE Enrichment