Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An exploitable flaw (CWE-306) in the Self Update Framework of Oracle Enterprise Manager Base Platform permits a low‑privileged attacker with network access over HTTPS to compromise the entire platform, resulting in loss of confidentiality, integrity, and availability.

Affected Systems

Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are vulnerable.

Risk and Exploitability

The CVSS 3.1 score of 8.8 indicates high severity. With an EPSS score below 1% and no listing in KEV, the likelihood of widespread exploitation is currently low, but the attack vector inferred from the description involves a network‑based HTTPS connection and requires only local privileges to succeed. Once exploited, an attacker can assume full control of the affected system.

Generated by OpenCVE AI on August 4, 2026 at 05:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a non‑vulnerable version of Oracle Enterprise Manager Base Platform.
  • Disable or restrict the Self Update Framework component if it is not required for operations.
  • Use network segmentation and firewall rules to limit external HTTPS access to the Enterprise Manager instances.

Generated by OpenCVE AI on August 4, 2026 at 05:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Self Update Framework Vulnerability in Oracle Enterprise Manager Allows Remote Compromise

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Self Update Framework Vulnerability in Oracle Enterprise Manager Allows Remote Compromise

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:28:06.405Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47004

cve-icon Vulnrichment

Updated: 2026-07-23T14:24:41.649Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function