Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw within the Oracle Enterprise Manager Base Platform UI Framework allows an unauthenticated attacker with network connectivity over HTTPS to influence data operations on the platform. The vulnerability enables the attacker to gain the ability to update, insert, or delete data accessible to the platform, as well as read portions of that data, thereby compromising confidentiality and integrity for users who have legitimate login access. However, the attack requires user interaction from a person other than the attacker, as noted in the CVSS vector UI:R. This defect is a form of improper access control as it permits actions normally restricted to authenticated and authorized sessions.

Affected Systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. The issue resides in the UI layer of the platform and may also impact any other Oracle components that interact with these versions.

Risk and Exploitability

The CVSS 3.1 base score of 6.1 classifies the risk as moderate, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild at present. Because the vulnerability requires a user other than the attacker to provide interaction (e.g., clicking a link), it is not exploitable purely remotely, but an attacker who can coerce a user could potentially gain unauthorized data modification and read privileges. The scope change indicated by S:C in the CVSS vector means that the impact could spill over to other Oracle components that interact with the platform, enlarging potential damage. The vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog.

Generated by OpenCVE AI on August 3, 2026 at 00:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Enterprise Manager Base Platform patch that addresses the UI Framework access control weakness
  • Restrict HTTPS access to the platform to trusted internal networks or through a VPN to limit exposure to potential attackers
  • Enable comprehensive logging of UI activity and regularly review logs for sign‑of‑malicious interaction or unauthorized data operations

Generated by OpenCVE AI on August 3, 2026 at 00:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Enterprise Manager UI Allows Unauthorized Data Modification

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Oracle Enterprise Manager UI
Weaknesses CWE-284

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Oracle Enterprise Manager UI
Weaknesses CWE-284

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:14:25.274Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47002

cve-icon Vulnrichment

Updated: 2026-07-23T14:13:42.767Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')