Impact
A vulnerability exists in the Metadata Plugin component of Oracle Enterprise Manager Base Platform that permits an attacker with low privileges and network reachability over HTTPS to create, delete, or alter critical data. The flaw enables an attacker to change or remove data accessible through the platform, thereby breaching the integrity of the system’s stored information. The weakness corresponds to an access control deficiency, enabling data manipulation without appropriate authorization.
Affected Systems
Oracle Corporation’s Enterprise Manager Base Platform is affected, specifically versions 13.5 and 24.1. These releases expose the Metadata Plugin to the described flaw.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate severity with a high impact on integrity. The EPSS score is less than 1%, reflecting a low probability of exploitation in the wild at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is HTTPS traffic directed at the platform’s exposed interfaces, requiring only local network exposure and low privilege credentials to successfully alter data.
OpenCVE Enrichment