Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Deployment Library). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is found in the Deployment Library component of Oracle Enterprise Manager Base Platform and permits a remote attacker who already holds high‑privilege credentials to compromise the platform through a network interface exposed over HTTPS. The flaw allows the attacker to gain full control of the system, leading to loss of confidentiality, integrity, and availability. The weakness is classified as CWE‑284 (Improper Access Control), underscoring the privilege escalation potential.

Affected Systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These platforms are widely used for monitoring, deployment, and management of cloud and on‑premises assets. Because the vulnerability resides in the Deployment Library, other Oracle products that rely on this component could also be impacted when the platform is in scope.

Risk and Exploitability

The CVSS 3.1 score of 9.1 indicates critical severity, with a network attack vector, low complexity, high privileges, no user interaction, and scope change. The EPSS score of less than 1% suggests the vulnerability is currently rarely exploited in the wild and is not listed in CISA’s KEV catalog. Exploitation requires possession of high‑privilege accounts or the ability to acquire them beforehand; after establishing HTTPS connectivity, the attacker can trigger the flaw to achieve full platform takeover.

Generated by OpenCVE AI on August 13, 2026 at 20:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Enterprise Manager Base Platform security patch for versions 13.5 and 24.1.
  • Restrict inbound HTTPS traffic to the Enterprise Manager interface to trusted internal hosts or VLANs and block external access.
  • Enable comprehensive audit logging on the Enterprise Manager server and monitor for anomalous deployment or privileged activity indicative of an attempted compromise.

Generated by OpenCVE AI on August 13, 2026 at 20:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Exploit in Oracle Enterprise Manager Deployment Library

Wed, 12 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Exploit in Oracle Enterprise Manager Base Platform Deployment Library
Weaknesses CWE-862

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Exploit in Oracle Enterprise Manager Base Platform Deployment Library
Weaknesses CWE-284
CWE-862

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Deployment Library). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-18T03:56:18.360Z

Reserved: 2026-05-18T15:55:10.308Z

Link: CVE-2026-46875

cve-icon Vulnrichment

Updated: 2026-06-17T15:15:37.344Z

cve-icon NVD

Status : Modified

Published: 2026-06-17T10:54:05.230

Modified: 2026-06-18T04:16:53.773

Link: CVE-2026-46875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:15:03Z

Weaknesses