Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Web Services Framework component of Oracle Enterprise Manager Base Platform and allows an attacker with low privileges and network access over HTTPS to modify or delete data and to read a subset of data that should be protected. The impact is a compromise of confidentiality and integrity for the affected data, as indicated by the CVSS score of 5.4.

Affected Systems

Oracle Corporation's Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. These are the only product lines mentioned. The vulnerability is specific to the web services framework and affects the EMS Base Platform component of Oracle Enterprise Manager.

Risk and Exploitability

The CVSS base score of 5.4 denotes moderate risk. The EPSS score is less than 1%, suggesting a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. Its attack vector is presumed to be over HTTPS, given the network access requirement stated in the description. The threat is moderate because it requires only low privileged access and network connectivity, but it remains exploitable if an attacker can reach the HTTPS interface of the EMS Base Platform.

Generated by OpenCVE AI on August 4, 2026 at 05:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch for CVE-2026-47001 as listed in the official Oracle CPU Jul‑2026 advisory.
  • Restrict HTTPS access to the Oracle Enterprise Manager Base Platform to trusted hosts only, using firewall rules or network segmentation.
  • Enable audit logging on the EMS Base Platform and regularly review logs for unauthorized update, delete, or read operations.
  • Limit user privileges to the minimum required to perform their tasks, ensuring that low‑privileged accounts do not have unnecessary write permissions.

Generated by OpenCVE AI on August 4, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Web Services in Oracle Enterprise Manager Base Platform

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Web Services in Oracle Enterprise Manager Base Platform

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:05:58.779Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47001

cve-icon Vulnrichment

Updated: 2026-07-23T14:05:52.987Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses