Impact
This vulnerability is located in the Agent Next Gen component of the Oracle Enterprise Manager Base Platform. It enables an unauthenticated attacker to cause a complete denial‑of‑service by repeatedly crashing the platform and also grants unauthorized update, insert or delete rights to certain accessible data. The flaw therefore impacts integrity and availability but does not expose confidential information.
Affected Systems
Oracle Enterprise Manager Base Platform, versions 13.5 and 24.1. The issue resides in the Agent Next Gen component that is shipped with these releases.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 indicates a high severity vulnerability, primarily affecting availability and to a lesser degree integrity. The EPSS score of less than 1% suggests exploit attempts are unlikely but should not be discounted. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of widespread exploitation, yet the attack vector is simple: an unauthenticated attacker can target the platform over HTTPS and trigger the crash or data‑modification behavior without needing any credentials.
OpenCVE Enrichment