Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Enterprise Manager Base Platform is vulnerable through its Agent Next Gen component, which accepts HTTPS requests without proper authentication. An attacker who can reach the HTTPS interface can send a crafted request and read a limited set of platform data, such as configuration summaries or operational metrics, leading to a confidentiality breach. The flaw requires only network connectivity to the HTTPS service and does not provide privilege escalation or denial of service.

Affected Systems

Oracle Enterprise Manager Base Platform from Oracle Corporation is impacted, specifically versions 13.5 and 24.1. Those releases include the vulnerable Agent Next Gen component.

Risk and Exploitability

The CVSS 3.1 base score of 5.3 indicates moderate risk, while the EPSS score of <1% signals a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attack likelihood is driven by the simple network-based HTTPS vector, and the impact is confined to confidentiality; integrity and availability remain unaffected.

Generated by OpenCVE AI on August 3, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Enterprise Manager Base Platform patch or upgrade to a version that removes the vulnerability
  • Restrict inbound HTTPS connections to the platform to trusted IP ranges or internal network segments using firewalls or the platform’s own access controls
  • Enable and review audit logs for unauthorized HTTPS requests and anomalous data reads to detect ongoing exploit attempts

Generated by OpenCVE AI on August 3, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Read-Only Data Disclosure in Oracle Enterprise Manager Base Platform

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via HTTPS in Oracle Enterprise Manager Base Platform
Weaknesses CWE-200
CWE-285

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via HTTPS in Oracle Enterprise Manager Base Platform
Weaknesses CWE-200
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:16:16.975Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46986

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:36.749Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses