Impact
Easily exploitable vulnerability in the Metadata Plugin of Oracle Enterprise Manager Base Platform allows an unauthenticated attacker with network access over HTTP to compromise the platform. The vulnerability requires human interaction from another individual, typically by convincing them to access a special URL or trigger a request. Successful exploitation can result in full takeover of the platform, compromising confidentiality, integrity and availability.
Affected Systems
This affects Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The issue is confined to the Metadata Plugin component but can impact other integrated products due to the change of scope.
Risk and Exploitability
The CVSS 3.1 base score of 9.6 indicates a critical severity, while an EPSS score below 1% suggests a low probability of exploitation under current conditions. The vulnerability is not listed in CISA’s KEV catalog, but because it requires an additional authenticated user to interact, it may be exploit limited. Nonetheless, the potential impact of complete platform compromise warrants immediate attention.
OpenCVE Enrichment