Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Enterprise Manager Base Platform contains a flaw in the Connector Framework that permits an attacker with high‑privileged credentials who can reach the system over HTTPS to compromise the platform. The vulnerability can be exercised via a remote network connection and, if successful, gives the attacker full control over the platform, including all data and administrative functions. This weakness is classified as CWE‑284, an improper restriction of privileges.

Affected Systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are impacted. These releases are supported by Oracle Corporation and are often deployed in enterprise environments.

Risk and Exploitability

The CVSS v3.1 Base Score of 7.2 indicates severe impact on confidentiality, integrity and availability. The EPSS score is less than 1 %, suggesting limited real‑world exploitation to date, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote over HTTPS, requiring the attacker to have high‑privileged credentials or internal network access. Without a patch or network isolation, the flaw allows a complete takeover of the platform.

Generated by OpenCVE AI on August 4, 2026 at 17:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch referenced in Oracle’s CPU July 2026 alert (https://www.oracle.com/security-alerts/cpujul2026.html).
  • Restrict HTTPS access to the Oracle Enterprise Manager Base Platform to trusted IP ranges or networks.
  • Enforce least privilege by limiting the use of high‑privileged accounts and applying strict role‑based permissions.

Generated by OpenCVE AI on August 4, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Remote High‑Privilege HTTPS Takeover of Oracle Enterprise Manager Base Platform Connector Framework

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Remote High‑Privilege HTTPS Takeover of Oracle Enterprise Manager Base Platform Connector Framework

Mon, 27 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Oracle Enterprise Manager Base Platform Remote Takeover via HTTPS
Weaknesses CWE-287

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Oracle Enterprise Manager Base Platform Remote Takeover via HTTPS
Weaknesses CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:15:55.211Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46988

cve-icon Vulnrichment

Updated: 2026-07-23T15:10:00.937Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:03.923

Modified: 2026-07-24T19:00:02.133

Link: CVE-2026-46988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses