Impact
The vulnerability lies in the Web Services Framework component of Oracle Enterprise Manager Base Platform and allows an attacker with low privileges and network access over HTTPS to modify or delete data and to read a subset of data that should be protected. The impact is a compromise of confidentiality and integrity for the affected data, as indicated by the CVSS score of 5.4.
Affected Systems
Oracle Corporation's Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These are the only product lines mentioned. The vulnerability is specific to the web services framework and affects the EMS Base Platform component of Oracle Enterprise Manager.
Risk and Exploitability
The CVSS base score of 5.4 denotes moderate risk. The EPSS score is less than 1%, suggesting a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. Its attack vector is presumed to be over HTTPS, given the network access requirement stated in the description. The threat is moderate because it requires only low privileged access and network connectivity, but it remains exploitable if an attacker can reach the HTTPS interface of the EMS Base Platform.
OpenCVE Enrichment