Impact
The vulnerability in Oracle Enterprise Manager Base Platform allows an unauthenticated attacker with network access over HTTPS to read a limited set of platform‑accessible data without requiring credentials. The weakness results in a modest confidentiality impact, as the attacker can only gain read access to restricted information rather than full system control. It is classified as a moderate‑severity issue.
Affected Systems
Oracle Corporation’s Oracle Enterprise Manager Base Platform, versions 13.5 and 24.1, are affected. The flaw resides in the Agent Next Gen component and is documented in Oracle’s July 2026 security advisory.
Risk and Exploitability
The CVSS v3.1 base score of 5.3 indicates a moderate threat, and the EPSS score of less than 1% shows it is unlikely to be widely exploited at present. The vulnerability is not listed in CISA’s KEV catalogue, which further reduces immediate concern. Nonetheless, an attacker can gain access to sensitive data via HTTPS traffic observed by a malicious network actor. Remediation requires applying the vendor‑supplied update for the affected OEM versions.
OpenCVE Enrichment