Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Enterprise Manager Base Platform’s Enterprise Config Management component permits an unauthenticated attacker with network access over HTTP to bypass normal authorization controls. The vulnerability allows the attacker to modify, insert, or delete data; read a subset of data; and trigger a partial denial of service. The weakness is a lack of proper authorization enforcement (CWE‑284) and is reflected in a CVSS‑3.1 base score of 7.3, indicating moderate impacts to confidentiality, integrity, and availability.

Affected Systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. Anyone operating those versions and exposing the HTTP interface to a network—whether internal or external—faces risk. The vulnerability lies in the Enterprise Config Management component of the platform.

Risk and Exploitability

Exploitation requires only a crafted HTTP request without credentials, making the attack path simple. The EPSS score of less than 1 % indicates that widespread, opportunistic exploitation is currently unlikely, yet the lack of a CISA KEV listing does not mitigate the risk of targeted attacks against active deployments. Once executed, an attacker could alter monitoring configurations, delete asset records, or inject malicious settings, thereby compromising the integrity of the management platform and disrupting normal monitoring operations.

Generated by OpenCVE AI on August 4, 2026 at 05:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch or upgrade Oracle Enterprise Manager Base Platform to a version that fixes the authorization bypass, as detailed in Oracle’s CPU July 2026 advisory
  • Restrict network access to the platform’s HTTP interface using firewall rules, VPNs, or network segmentation to limit exposure to trusted administrative networks
  • Audit configuration files and database entries for unauthorized changes, and enable alerts on critical object modifications to detect potential exploitation

Generated by OpenCVE AI on August 4, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass in Oracle Enterprise Manager Base Platform

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Authorization Bypass Enables Data Modification and Partial Denial in Oracle Enterprise Manager Base Platform

Mon, 27 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Authorization Bypass Enables Data Modification and Partial Denial in Oracle Enterprise Manager Base Platform

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T13:34:26.867Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46990

cve-icon Vulnrichment

Updated: 2026-07-23T13:34:04.707Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses