Impact
A vulnerability exists in the Security Framework component of Oracle Enterprise Manager Base Platform 24.1 that allows an attacker with low privileges and network access via HTTPS to perform unauthorized update, insert, or delete operations on data accessible to the platform. This flaw is a Cross‑Site Request Forgery (CWE‑352) that can be triggered through crafted HTTPS requests. The CVSS 3.1 base score of 3.5 highlights that the primary impact is on integrity, with no impact on confidentiality or availability. Successful exploitation requires human interaction from a person other than the attacker, indicating that the attack is not fully automated but can be assisted by social engineering or credential disclosure.
Affected Systems
Oracle Enterprise Manager Base Platform, version 24.1, as identified by the CNA and the documented CPE string.
Risk and Exploitability
The CVSS score of 3.5 combined with an EPSS score of less than 1% suggests that while exploitation is possible, it is considered low probability. The attack vector is network-based (HTTPS), with a low attack complexity and requires only low privileged credentials. The vulnerability is not currently listed in the CISA KEV catalog. Because of the low score and the requirement of human interaction, the risk is moderate but should still be addressed promptly to prevent potential unauthorized data changes.
OpenCVE Enrichment