Impact
The vulnerability exists in Oracle Enterprise Manager Base Platform, specifically the Enterprise Config Management component. It is a CWE-306 weakness involving improper authentication. Attackers with network access over HTTPS and lower privileges can exploit the flaw to compromise and potentially take over the platform. The flaw grants complete control and results in confidentiality, integrity, and availability losses, as indicated by the CVSS 3.1 base score of 8.8.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These versions are listed as vulnerable by the CNA and no additional sub‑version granularity is provided.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity, while an EPSS of <1% suggests that widespread exploitation is currently unlikely. The risk is amplified by the fact that the flaw is exploitable remotely via a standard HTTPS connection with no user interaction required. The attacker’s only requirement is to reach the exposed HTTPS interface. Because the vulnerability is not listed in the CISA KEV catalog, no public exploits are currently documented.
OpenCVE Enrichment