Impact
The vulnerability resides in the Metadata Plugin component of Oracle Enterprise Manager Base Platform. This weakness is classified as CWE‑601 Open Redirect. An unauthenticated attacker with network access to the HTTPS interface can trigger exploitation of the plugin. Successful exploitation results in full takeover of the platform, leading to confidentiality, integrity, and availability compromise. The attack requires human interaction from a user other than the attacker, indicating a UI‑based exploitation path.
Affected Systems
Affected products include Oracle Enterprise Manager Base Platform, specifically versions 13.5 and 24.1. Any installation of these versions running the Metadata Plugin is potentially vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 reflects high severity. The EPSS value is below 1%, suggesting low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only HTTPS access and a user action, making it easily reachable over the network but still dependent on a second human to confirm the interaction.
OpenCVE Enrichment