Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Metadata Plugin of Oracle Enterprise Manager Base Platform that allows a low‑privileged attacker who can reach the HTTPS interface to execute arbitrary code on the server. The flaw leads to full compromise of the platform, exposing confidential data, and enabling modification of system integrity and availability. Based on the description, it is inferred that the weakness resembles an improper access control defect, allowing a low‑privileged attacker to attain administrative authority.

Affected Systems

Oracle Enterprise Manager Base Platform, versions 13.5 and 24.1, from Oracle Corporation, are affected.

Risk and Exploitability

The CVSS v3.1 score of 9.9 indicates critical severity. The EPSS score is under 1%, suggesting low current exploitation probability, and it is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is network‑based over HTTPS with low required privileges, and successful exploitation results in complete takeover of the target system. Operators should treat this as a high‑risk exposure even with a low exploitation likelihood.

Generated by OpenCVE AI on June 17, 2026 at 19:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch that addresses the Metadata Plugin vulnerability
  • Configure firewall or VPN controls to limit HTTPS access to the Enterprise Manager Base Platform to trusted administrative networks
  • Enforce strict least‑privilege principals for all user accounts interacting with the platform and monitor for unauthorized activity

Generated by OpenCVE AI on June 17, 2026 at 19:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:38:43.622Z

Reserved: 2026-05-18T15:55:10.306Z

Link: CVE-2026-46852

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T01:00:15Z

Weaknesses

No weakness.