Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Agent Next Gen component of Oracle Enterprise Manager Base Platform. The weakness is a missing access control (CWE-284). An attacker who can reach the platform over HTTPS, without authentication, can read a subset of data that should be protected. The vulnerability does not grant code execution, modify data, or impact availability. The assessment is reflected in CVSS 3.1 with a base score of 5.3, indicating a low confidentiality impact.

Affected Systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These products are delivered by Oracle Corporation and are used by environments that require centralized monitoring and management of Oracle software and hardware resources.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. The CVSS 3.1 base score of 5.3 indicates a moderate confidentiality impact. Nevertheless, the attack vector is network-based, relies only on HTTPS connectivity, and requires no authentication, making it relatively easy for an adversary with network access to conduct the read-only disclosure attack.

Generated by OpenCVE AI on August 3, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a version that includes the fix for the Agent Next Gen component
  • Restrict network access to the Oracle Enterprise Manager Base Platform to trusted hosts only
  • Monitor enterprise manager logs for unauthorized data access attempts

Generated by OpenCVE AI on August 3, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Data Disclosure in Oracle Enterprise Manager Base Platform

Mon, 27 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Read Access via HTTPS in Oracle Enterprise Manager Base Platform Agent Next Gen
Weaknesses CWE-200

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Read Access via HTTPS in Oracle Enterprise Manager Base Platform Agent Next Gen
Weaknesses CWE-200

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:16:30.726Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46985

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:37.821Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses