Impact
An exploitable flaw (CWE-306) in the Self Update Framework of Oracle Enterprise Manager Base Platform permits a low‑privileged attacker with network access over HTTPS to compromise the entire platform, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are vulnerable.
Risk and Exploitability
The CVSS 3.1 score of 8.8 indicates high severity. With an EPSS score below 1% and no listing in KEV, the likelihood of widespread exploitation is currently low, but the attack vector inferred from the description involves a network‑based HTTPS connection and requires only local privileges to succeed. Once exploited, an attacker can assume full control of the affected system.
OpenCVE Enrichment