Impact
The vulnerability exists in the UI Framework component of Oracle Enterprise Manager Base Platform and allows an attack that does not require authentication. An attacker who can reach the HTTPS interface can obtain unauthorized access to critical data or, at a minimum, all data available through the platform. This is a confidentiality‑impacting weakness that does not affect integrity or availability. The weakness aligns with improper access control, enabling elevation of privilege for unauthenticated users.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. Users running these versions should verify whether the July 2026 patch is installed and, if not, plan an update. The vulnerability affects all components that expose the HTTPS UI interfaces of the platform.
Risk and Exploitability
The CVSS 3.1 base score of 5.9 indicates a moderate risk level with a confidentiality impact only. The EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a network‑based HTTPS connection to the UI, requiring no authentication and thus posing an elevated threat to organizations that expose this interface publicly or to untrusted networks.
OpenCVE Enrichment