Executive brief
A critical vulnerability exists in Oracle Siebel Cloud Manager, a tool used to manage and deploy Siebel CRM applications in cloud environments. An attacker with access to the local network segment could potentially take full control of the application. This could lead to a total loss of data confidentiality and service availability, potentially impacting other integrated business systems.
Technical details
This vulnerability (CWE-284) exists in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It is classified as difficult to exploit because it requires the attacker to have access to the specific physical communication segment (adjacent network) where the hardware executes. No authentication or user interaction is required for exploitation. A successful attack results in a 'scope change,' meaning the attacker can potentially impact products beyond the Siebel CRM environment itself. The exploit can lead to a complete takeover of the affected Siebel CRM Cloud Applications instance, impacting confidentiality, integrity, and availability. Affected versions range from 17.0 through 26.5.
Affected products
- Oracle Siebel CRM Cloud Applications 17.0-26.5
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published