Impact
The Oracle Enterprise Manager Base Platform is vulnerable through its Agent Next Gen component, which accepts HTTPS requests without proper authentication. An attacker who can reach the HTTPS interface can send a crafted request and read a limited set of platform data, such as configuration summaries or operational metrics, leading to a confidentiality breach. The flaw requires only network connectivity to the HTTPS service and does not provide privilege escalation or denial of service.
Affected Systems
Oracle Enterprise Manager Base Platform from Oracle Corporation is impacted, specifically versions 13.5 and 24.1. Those releases include the vulnerable Agent Next Gen component.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates moderate risk, while the EPSS score of <1% signals a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attack likelihood is driven by the simple network-based HTTPS vector, and the impact is confined to confidentiality; integrity and availability remain unaffected.
OpenCVE Enrichment