Impact
The CVE exposes an authorization bypass in the Enterprise Config Management component of Oracle Enterprise Manager Base Platform, allowing an attacker with low‑privileged or local access to the host to perform unauthorized update, insert, or delete operations on platform data, as well as read restricted data. The weakness stems from improper validation of user privileges (CWE‑284) and results in both confidentiality and integrity compromise of the platform’s configuration and operational information.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These are the only versions listed in the CNA release and are the ones where the vulnerability is present.
Risk and Exploitability
The CVSS 3.1 score of 4.4 indicates low severity, and the EPSS score of less than 1 % implies a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local or low‑privileged access to the host running the base platform; thus the likely attack vector is a low‑privileged local attacker or compromised service account.
OpenCVE Enrichment