Impact
Oracle Enterprise Manager Base Platform is impacted by an improper access control flaw that allows an attacker with only low privileges and network access via HTTPS to add, delete, or alter critical data. The vulnerability resides in the Agent Next Gen component and can provide an attacker with complete control over all data governed by the platform, effectively expanding the attack scope beyond the immediate target.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1, specifically the Agent Next Gen component of the Base Platform, are vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.2 indicates a high severity impact on confidentiality and integrity. However, the EPSS score is less than 1%, suggesting a low likelihood of exploitation today, and the vulnerability has not been listed in CISA’s KEV catalog. Attackers would need remote access over HTTPS to the platform, leveraging the low privilege requirement to execute the flaw.
OpenCVE Enrichment