Impact
The Metadata Plugin component of Oracle Enterprise Manager Base Platform is vulnerable to an easily exploitable flaw that permits a low‑privileged attacker with HTTPS access to create, delete or modify critical data and also read a subset of platform data. The vulnerability leads to confidentiality and integrity breaches as defined by the CVSS vector, which highlights low confidentiality impact but high integrity impact.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected by this issue. Only these releases contain the vulnerable Metadata Plugin component and are mentioned in Oracle’s July 2026 CPU advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 signifies moderate severity, driven largely by the high integrity impact. The EPSS score of <1% suggests that exploitation is currently rare, and the vulnerability is not included in the CISA KEV catalog. Successful exploitation requires network reachability to the HTTPS interface and only low privileges, which limits but does not eliminate the risk.
OpenCVE Enrichment