Impact
A flaw in the Metadata Plugin component of Oracle Enterprise Manager Base Platform enables an unauthenticated attacker to send crafted HTTP requests that can compromise the platform. The impact described is the potential takeover of Oracle Enterprise Manager Base Platform; while the official text does not explicitly state remote code execution, the ability to take over a platform implies that code execution may be achievable, which is an inference based on the stated impact.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. Users of these releases should verify that they have applied the relevant security updates or upgraded to versions that incorporate the fix.
Risk and Exploitability
The CVSS 3.1 base score of 9.6 classifies this flaw as critical. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The stated attack vector is network access via HTTP, with no credentials required. However, successful exploitation requires human interaction from a person other than the attacker, indicating that the exploit is not fully automated. Organizations with exposed Metadata Plugin endpoints face a significant risk if the platform remains unpatched.
OpenCVE Enrichment