Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Security Framework component of Oracle Enterprise Manager Base Platform 24.1 that allows an attacker with low privileges and network access via HTTPS to perform unauthorized update, insert, or delete operations on data accessible to the platform. This flaw is a Cross‑Site Request Forgery (CWE‑352) that can be triggered through crafted HTTPS requests. The CVSS 3.1 base score of 3.5 highlights that the primary impact is on integrity, with no impact on confidentiality or availability. Successful exploitation requires human interaction from a person other than the attacker, indicating that the attack is not fully automated but can be assisted by social engineering or credential disclosure.

Affected Systems

Oracle Enterprise Manager Base Platform, version 24.1, as identified by the CNA and the documented CPE string.

Risk and Exploitability

The CVSS score of 3.5 combined with an EPSS score of less than 1% suggests that while exploitation is possible, it is considered low probability. The attack vector is network-based (HTTPS), with a low attack complexity and requires only low privileged credentials. The vulnerability is not currently listed in the CISA KEV catalog. Because of the low score and the requirement of human interaction, the risk is moderate but should still be addressed promptly to prevent potential unauthorized data changes.

Generated by OpenCVE AI on August 3, 2026 at 00:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Enterprise Manager Base Platform patch or upgrade to a supported version that addresses the Security Framework flaw.
  • Configure or enable anti‑CSRF protection such as synchronizer tokens or same‑site cookie flags for all HTTPS endpoints interacting with the Security Framework to mitigate the vulnerability.
  • Restrict HTTPS access to the platform to trusted administrators and disable or secure the Security Framework features until a patch is available.
  • Implement database and application logging to detect unauthorized insert, update, or delete operations, and configure alerts for anomalous activity.

Generated by OpenCVE AI on August 3, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Integrity Compromise via HTTPS in Oracle Enterprise Manager Base Platform 24.1

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Integrity Compromise via HTTPS in Oracle Enterprise Manager Base Platform 24.1

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:04:41.198Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47000

cve-icon Vulnrichment

Updated: 2026-07-23T14:03:58.878Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)