Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability, an access‑control flaw (CWE‑284), in Oracle Enterprise Manager Base Platform enables a low‑privileged attacker who can reach the system through HTTPS to gain unauthorized access to critical data. The flaw allows the attacker to bypass normal access controls and read data accessible to the management platform, potentially compromising the confidentiality of all data exposed through the platform.

Affected Systems

Affected product concerns Oracle Enterprise Manager Base Platform for versions 13.5 and 24.1. The vulnerability is located in the Application Service Level Management component and may affect other Oracle products connected to the Base Platform. The issue applies to deployments that expose the HTTPS interface to untrusted networks.

Risk and Exploitability

The CVSS v3.1 score of 7.7 indicates a high severity vulnerability that primarily impacts confidentiality (C:H). The EPSS score is less than 1%, suggesting that exploitation is not widespread yet, and the flaw is not currently listed in the CISA KEV catalogue. However, because the attack vector is through a public HTTPS interface and only requires low privileges, the risk remains significant for exposed environments. Exploitation would likely involve forging or manipulating HTTPS requests to the management service, bypassing authentication and retrieving protected data.

Generated by OpenCVE AI on August 4, 2026 at 05:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch or upgrade for Enterprise Manager Base Platform versions 13.5 and 24.1, as detailed in the Oracle CPU July 2026 advisory.
  • Restrict HTTPS traffic to the Base Platform to trusted networks or VPN connections, and enforce strong authentication for all users.
  • Disable or remove unnecessary services and limit user permissions on the platform to the minimum required for operational roles.

Generated by OpenCVE AI on August 4, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTPS Access Control Flaw in Oracle Enterprise Manager Base Platform

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Enterprise Manager Base Platform Allowing Unauthorized Data Access

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Enterprise Manager Base Platform Allowing Unauthorized Data Access

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:16:06.586Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46987

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:35.657Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses