Impact
A flaw in the Self Update Framework component of Oracle Enterprise Manager Base Platform allows a high privileged attacker with network access via HTTPS to compromise the platform. This can lead to full takeover, jeopardising confidentiality, integrity and availability of all managed resources. The weakness is a direct authorization bypass.
Affected Systems
Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 are affected. Organizations using either release should verify their installation and assess whether the Self Update Framework is exposed to the network.
Risk and Exploitability
The CVSS score of 7.2 marks this as high severity. The EPSS value is listed as <1%, indicating a low but non-zero exploitation probability. It is not currently referenced in the CISA KEV catalog. The likely attack path requires remote HTTPS connectivity to the Self Update Framework endpoint and a user account with high privileges, allowing the attacker to take control of the platform process.
OpenCVE Enrichment