Impact
The vulnerability resides in the Agent component of Oracle Enterprise Manager for Systems Infrastructure. A low‑privileged user who can log on to the infrastructure can exploit this flaw to compromise the product. Successful exploitation would allow the attacker to take full control of the instance, compromising confidentiality, integrity, and availability. The weakness appears to be a privilege‑escalation misconfiguration rather than code injection or denial of service.
Affected Systems
Affected installations are Oracle Enterprise Manager for Systems Infrastructure version 13.5 and 24.1. These appear as separate product releases. Installations of any other version or product type are not known to be at risk.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity local attack with low authentication and no user interaction. Exploitability is considered easy as the description states the flaw is easily exploitable. The EPSS is unavailable; the vulnerability is not currently listed in the CISA KEV. Attackers would need only local presence and low privilege to gain full control, making this a significant risk for exposed or shared environments.
OpenCVE Enrichment