Impact
The vulnerability arises in the Oracle Management Service component of Oracle Enterprise Manager Base Platform, enabling an unauthenticated attacker to gain full control over the system. The flaw is a classic access control issue (CWE‑284) that allows bypassing authentication and leads to loss of confidentiality, integrity, and availability. Attackers can exfiltrate data, alter configurations, and disrupt services.
Affected Systems
Affected editions are Oracle Enterprise Manager Base Platform 13.5 and 24.1. Both releases contain the vulnerable component, and hosts that expose the HTTP interface to external networks are at risk.
Risk and Exploitability
The CVSS score of 9.8 signals a critical flaw. Although the EPSS score is below 1%, indicating a low current exploitation probability, the issue is not listed in the CISA KEV catalog and no workaround is available; therefore, administrators must act quickly to secure the environment. The flaw is exploitable over HTTP without authentication, suggesting a direct remote interaction path.
OpenCVE Enrichment