Impact
A flaw within the Oracle Enterprise Manager Base Platform UI Framework allows an unauthenticated attacker with network connectivity over HTTPS to influence data operations on the platform. The vulnerability enables the attacker to gain the ability to update, insert, or delete data accessible to the platform, as well as read portions of that data, thereby compromising confidentiality and integrity for users who have legitimate login access. However, the attack requires user interaction from a person other than the attacker, as noted in the CVSS vector UI:R. This defect is a form of improper access control as it permits actions normally restricted to authenticated and authorized sessions.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. The issue resides in the UI layer of the platform and may also impact any other Oracle components that interact with these versions.
Risk and Exploitability
The CVSS 3.1 base score of 6.1 classifies the risk as moderate, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild at present. Because the vulnerability requires a user other than the attacker to provide interaction (e.g., clicking a link), it is not exploitable purely remotely, but an attacker who can coerce a user could potentially gain unauthorized data modification and read privileges. The scope change indicated by S:C in the CVSS vector means that the impact could spill over to other Oracle components that interact with the platform, enlarging potential damage. The vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment