Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Metadata Plugin component of Oracle Enterprise Manager Base Platform. This weakness is classified as CWE‑601 Open Redirect. An unauthenticated attacker with network access to the HTTPS interface can trigger exploitation of the plugin. Successful exploitation results in full takeover of the platform, leading to confidentiality, integrity, and availability compromise. The attack requires human interaction from a user other than the attacker, indicating a UI‑based exploitation path.

Affected Systems

Affected products include Oracle Enterprise Manager Base Platform, specifically versions 13.5 and 24.1. Any installation of these versions running the Metadata Plugin is potentially vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 reflects high severity. The EPSS value is below 1%, suggesting low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only HTTPS access and a user action, making it easily reachable over the network but still dependent on a second human to confirm the interaction.

Generated by OpenCVE AI on August 4, 2026 at 05:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch for the Metadata Plugin in Oracle Enterprise Manager Base Platform released in the CPU July 2026 advisory.
  • Validate or whitelist redirect URLs used by the Metadata Plugin to mitigate the open redirect (CWE‑601).
  • Disable the Metadata Plugin or restrict access to it until the patch is applied if the feature is not required.
  • Configure firewall rules to limit HTTPS traffic to the Oracle Enterprise Manager Base Platform to trusted IP addresses.
  • Enable detailed logging of HTTPS requests to the Metadata Plugin and monitor for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Oracle Enterprise Manager Base Platform Open Redirect Vulnerability Enables Full Takeover

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Metadata Plugin Exploit Compromising Oracle Enterprise Manager Base Platform
Weaknesses CWE-200
CWE-284

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Metadata Plugin Exploit Compromising Oracle Enterprise Manager Base Platform
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:00:22.441Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-46998

cve-icon Vulnrichment

Updated: 2026-07-23T13:59:32.306Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')