Impact
A flaw in Oracle Enterprise Manager Base Platform’s Enterprise Config Management component permits an unauthenticated attacker with network access over HTTP to bypass normal authorization controls. The vulnerability allows the attacker to modify, insert, or delete data; read a subset of data; and trigger a partial denial of service. The weakness is a lack of proper authorization enforcement (CWE‑284) and is reflected in a CVSS‑3.1 base score of 7.3, indicating moderate impacts to confidentiality, integrity, and availability.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. Anyone operating those versions and exposing the HTTP interface to a network—whether internal or external—faces risk. The vulnerability lies in the Enterprise Config Management component of the platform.
Risk and Exploitability
Exploitation requires only a crafted HTTP request without credentials, making the attack path simple. The EPSS score of less than 1 % indicates that widespread, opportunistic exploitation is currently unlikely, yet the lack of a CISA KEV listing does not mitigate the risk of targeted attacks against active deployments. Once executed, an attacker could alter monitoring configurations, delete asset records, or inject malicious settings, thereby compromising the integrity of the management platform and disrupting normal monitoring operations.
OpenCVE Enrichment