Impact
A flaw in the Agent Next Gen component of Oracle Enterprise Manager Base Platform allows an attacker to send HTTPS requests without any authentication and take complete control of the platform. The weakness, classified as CWE-284 Improper Access Control, results in loss of confidentiality, integrity and availability for all data and services managed by the platform. Successful exploitation gives the attacker full administrative rights to the system, enabling arbitrary configuration, data exfiltration, or further lateral movement within the managed environment.
Affected Systems
The affected vendor is Oracle Corporation, specifically the Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. These releases expose the Agent Next Gen service via HTTPS without enforcing proper access control. Earlier or later versions not listed in the known affected versions are not known to be impacted.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 marks this as critical, with a full impact on confidentiality, integrity and availability. The EPSS score is less than 1% indicating a low current exploitation probability, and the vulnerability has not been listed in the CISA KEV catalog. However, any system exposed to the public or untrusted networks can be targeted trivially: an attacker only needs network access to the HTTPS interface and no credentials to succeed, making the risk high for exposed installations.
OpenCVE Enrichment