Impact
A vulnerability exists in the Metadata Plugin of Oracle Enterprise Manager Base Platform that allows a low‑privileged attacker who can reach the HTTPS interface to execute arbitrary code on the server. The flaw leads to full compromise of the platform, exposing confidential data, and enabling modification of system integrity and availability. Based on the description, it is inferred that the weakness resembles an improper access control defect, allowing a low‑privileged attacker to attain administrative authority.
Affected Systems
Oracle Enterprise Manager Base Platform, versions 13.5 and 24.1, from Oracle Corporation, are affected.
Risk and Exploitability
The CVSS v3.1 score of 9.9 indicates critical severity. The EPSS score is under 1%, suggesting low current exploitation probability, and it is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is network‑based over HTTPS with low required privileges, and successful exploitation results in complete takeover of the target system. Operators should treat this as a high‑risk exposure even with a low exploitation likelihood.
OpenCVE Enrichment