Impact
The flaw resides in the Agent Next Gen component of Oracle Enterprise Manager Base Platform. The weakness is a missing access control (CWE-284). An attacker who can reach the platform over HTTPS, without authentication, can read a subset of data that should be protected. The vulnerability does not grant code execution, modify data, or impact availability. The assessment is reflected in CVSS 3.1 with a base score of 5.3, indicating a low confidentiality impact.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These products are delivered by Oracle Corporation and are used by environments that require centralized monitoring and management of Oracle software and hardware resources.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. The CVSS 3.1 base score of 5.3 indicates a moderate confidentiality impact. Nevertheless, the attack vector is network-based, relies only on HTTPS connectivity, and requires no authentication, making it relatively easy for an adversary with network access to conduct the read-only disclosure attack.
OpenCVE Enrichment