Impact
The Oracle Enterprise Manager Base Platform contains a flaw in the Connector Framework that permits an attacker with high‑privileged credentials who can reach the system over HTTPS to compromise the platform. The vulnerability can be exercised via a remote network connection and, if successful, gives the attacker full control over the platform, including all data and administrative functions. This weakness is classified as CWE‑284, an improper restriction of privileges.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are impacted. These releases are supported by Oracle Corporation and are often deployed in enterprise environments.
Risk and Exploitability
The CVSS v3.1 Base Score of 7.2 indicates severe impact on confidentiality, integrity and availability. The EPSS score is less than 1 %, suggesting limited real‑world exploitation to date, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote over HTTPS, requiring the attacker to have high‑privileged credentials or internal network access. Without a patch or network isolation, the flaw allows a complete takeover of the platform.
OpenCVE Enrichment