Impact
The Oracle Enterprise Manager Base Platform contains a flaw in its Self Update Framework that permits a remote attacker with high‑level credentials to execute arbitrary code through the HTTPS endpoint. This defect, classified as CWE‑284 (Improper Access Control), can lead to a full takeover of the platform, compromising confidentiality, integrity and availability of managed assets.
Affected Systems
Affected versions are Oracle Enterprise Manager Base Platform 13.5 and 24.1, as identified by the vendor and the CPE data.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 7.2 (high severity) and an EPSS score below 1 %, indicating a low current exploitation likelihood. It is not listed in CISA’s KEV catalog, but the remote AV:N vector combined with high privileged exploitation potential means that, if an attacker gains access, the impact could be total platform compromise. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) reflects that network‑based attackers must be authenticated with high privileges and leverage the HTTPS interface to trigger the flaw.
OpenCVE Enrichment