Impact
Oracle Enterprise Manager Base Platform’s UI Framework contains a broken access control flaw that allows an attacker with low‑privileged network access over HTTPS to obtain read, update, insert, or delete rights to platform data and to trigger a partial denial of service. The vulnerability can expose confidential information, compromise data integrity, and disrupt platform availability.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. The flaw resides in the web UI component and is reachable through the platform’s HTTPS interface. All operating systems supported by those releases are impacted, and the vulnerability’s scope change can affect other Oracle products built on the base platform.
Risk and Exploitability
The CVSS v3.1 base score of 9.1 indicates a high severity vulnerability that can be exploited by an adversary with low‑privileged credentials or legitimate access to the platform’s HTTPS service. The EPSS score of <1% suggests a low probability of exploitation in the wild, but the network‑based attack surface and lack of requirement for elevated privileges make it an attractive target for attackers who can reach the HTTPS port. The vulnerability is not listed in the CISA KEV catalog. An attacker would connect to the platform over HTTPS, use the flaw to gain unauthorized data access or modify data, and could cause a partial denial of service.
OpenCVE Enrichment