Impact
A vulnerability in Oracle Enterprise Manager Base Platform allows an attacker with low privileges who can reach the system over HTTP to take full control of the platform. The flaw can be exploited simply by connecting to the web interface, without the need for elevated credentials or prior access. Successful exploitation results in a full compromise of confidentiality, integrity, and availability, essentially giving the attacker the same privileges as the platform process and the ability to affect downstream services.
Affected Systems
The flaw affects Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. These are the only supported releases listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 9.9 reflects the severe impact and the low attack effort. The EPSS score of less than 1% suggests that, while the attack is technically easy, it is expected to be uncommon at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog, so it has not yet been observed in the wild, but its scope‑changing nature (S:C) means that compromising the target platform could also affect other interconnected Oracle products. An attacker would likely initiate the exploit over standard HTTP traffic, which is readily available on most networks, making the attack vector highly convenient.
OpenCVE Enrichment