Impact
The vulnerability resides in the Agent Next Gen component of Oracle Enterprise Manager Base Platform and allows a low‑privileged attacker to execute code and compromise the platform. If successfully exploited, the attacker can fully take control, leading to complete loss of confidentiality, integrity, and availability of the system. The CVSS vector indicates a network‑based attack with low authentication and no user interaction, confirming the high impact of this flaw.
Affected Systems
Oracle Corporation’s Oracle Enterprise Manager Base Platform is affected in versions 13.5 and 24.1. The platform is used for monitoring and managing enterprise IT infrastructure, and the vulnerability specifically targets the Agent Next Gen component.
Risk and Exploitability
The CVSS base score of 8.8 reflects a high severity, while the EPSS score of less than 1% suggests that exploitation probability is currently very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based SSH connection that an attacker with low privileges can use to log into the platform and then exploit the Agent Next Gen component to gain full control. Without mitigation, an adversary could compromise the entire management platform.
OpenCVE Enrichment