Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Enterprise Manager Base Platform allows an unauthenticated attacker with network access over HTTPS to read a limited set of platform‑accessible data without requiring credentials. The weakness results in a modest confidentiality impact, as the attacker can only gain read access to restricted information rather than full system control. It is classified as a moderate‑severity issue.

Affected Systems

Oracle Corporation’s Oracle Enterprise Manager Base Platform, versions 13.5 and 24.1, are affected. The flaw resides in the Agent Next Gen component and is documented in Oracle’s July 2026 security advisory.

Risk and Exploitability

The CVSS v3.1 base score of 5.3 indicates a moderate threat, and the EPSS score of less than 1% shows it is unlikely to be widely exploited at present. The vulnerability is not listed in CISA’s KEV catalogue, which further reduces immediate concern. Nonetheless, an attacker can gain access to sensitive data via HTTPS traffic observed by a malicious network actor. Remediation requires applying the vendor‑supplied update for the affected OEM versions.

Generated by OpenCVE AI on August 4, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Oracle Enterprise Manager Base Platform 13.5 or 24.1 as provided in the July 2026 security alert.
  • Restrict network access to the OEM management endpoint to trusted hosts or subnets and enforce strong authentication for all management connections.
  • Continuously monitor audit logs for unauthorized read attempts and enforce multi‑factor authentication for OEM users.

Generated by OpenCVE AI on August 4, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Read Access via HTTPS in Oracle Enterprise Manager Base Platform

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Read Access in Oracle Enterprise Manager Base Platform
Weaknesses CWE-200

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Read Access in Oracle Enterprise Manager Base Platform
Weaknesses CWE-200

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:16:39.821Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46984

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:39.102Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:03.460

Modified: 2026-07-24T18:58:01.277

Link: CVE-2026-46984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses