Impact
This vulnerability, an access‑control flaw (CWE‑284), in Oracle Enterprise Manager Base Platform enables a low‑privileged attacker who can reach the system through HTTPS to gain unauthorized access to critical data. The flaw allows the attacker to bypass normal access controls and read data accessible to the management platform, potentially compromising the confidentiality of all data exposed through the platform.
Affected Systems
Affected product concerns Oracle Enterprise Manager Base Platform for versions 13.5 and 24.1. The vulnerability is located in the Application Service Level Management component and may affect other Oracle products connected to the Base Platform. The issue applies to deployments that expose the HTTPS interface to untrusted networks.
Risk and Exploitability
The CVSS v3.1 score of 7.7 indicates a high severity vulnerability that primarily impacts confidentiality (C:H). The EPSS score is less than 1%, suggesting that exploitation is not widespread yet, and the flaw is not currently listed in the CISA KEV catalogue. However, because the attack vector is through a public HTTPS interface and only requires low privileges, the risk remains significant for exposed environments. Exploitation would likely involve forging or manipulating HTTPS requests to the management service, bypassing authentication and retrieving protected data.
OpenCVE Enrichment