Impact
A vulnerability in the Metadata Plugin component of Oracle Enterprise Manager Base Platform permits an unauthenticated attacker with network access via HTTP to compromise the platform. The flaw can lead to full control over the affected system, affecting confidentiality, integrity, and availability of the platform.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are subject to the vulnerability. These releases should be verified for available security updates or upgraded to a version that includes the fix.
Risk and Exploitability
The CVSS 3.1 base score of 9.6 classifies the error as critical. The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers gain access over the network without credentials via HTTP, but successful exploitation requires human interaction from a user other than the attacker, which limits the potential for fully automated attacks.
OpenCVE Enrichment