Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Enterprise Manager Base Platform contains a flaw in its Self Update Framework that permits a remote attacker with high‑level credentials to execute arbitrary code through the HTTPS endpoint. This defect, classified as CWE‑284 (Improper Access Control), can lead to a full takeover of the platform, compromising confidentiality, integrity and availability of managed assets.

Affected Systems

Affected versions are Oracle Enterprise Manager Base Platform 13.5 and 24.1, as identified by the vendor and the CPE data.

Risk and Exploitability

The vulnerability has a CVSS 3.1 base score of 7.2 (high severity) and an EPSS score below 1 %, indicating a low current exploitation likelihood. It is not listed in CISA’s KEV catalog, but the remote AV:N vector combined with high privileged exploitation potential means that, if an attacker gains access, the impact could be total platform compromise. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) reflects that network‑based attackers must be authenticated with high privileges and leverage the HTTPS interface to trigger the flaw.

Generated by OpenCVE AI on August 3, 2026 at 00:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses CVE‑2026‑47005.
  • Restrict inbound HTTPS traffic to the Oracle Enterprise Manager Base Platform to trusted hosts or IP ranges to limit exposure to the update endpoint.
  • If possible, disable or restrict the Self Update Framework feature or block the update URLs until a patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Oracle Enterprise Manager Self Update Framework Remote Code Execution Vulnerability

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Code Execution via Self Update Framework in Oracle Enterprise Manager Base Platform
Weaknesses CWE-94

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Code Execution via Self Update Framework in Oracle Enterprise Manager Base Platform
Weaknesses CWE-94

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:39:42.475Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47005

cve-icon Vulnrichment

Updated: 2026-07-23T14:31:41.063Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses