Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Application Config Console component of Oracle Enterprise Manager Base Platform allows an attacker with low privileges and network access to HTTP to bypass normal access controls and gain full control over the platform, potentially exposing confidential data, altering system configuration, and disrupting availability.

Affected Systems

Oracle Enterprise Manager Base Platform version 13.5 and 24.1 are affected, as identified by the vendor. The weakness exists in the Application Config Console component, which is reachable through standard HTTP interfaces.

Risk and Exploitability

This flaw has a CVSS base score of 8.8, indicating high severity with complete confidentiality, integrity, and availability impact. While EPSS is not available, the lack of a KEV listing does not mitigate the risk; the vulnerability can be exploited over the network by a low privileged user, potentially resulting in full takeover if no network segmentation or strict access restrictions exist. Attackers should be assumed capable of reaching the HTTP interface.

Generated by OpenCVE AI on August 21, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Oracle patch or update for Oracle Enterprise Manager Base Platform 13.5 and 24.1 from the Oracle Security Alerts webpage.
  • Restrict HTTP access to the Enterprise Manager Base Platform to trusted network segments or administrators only, using firewall rules or VPN.
  • Configure the platform to enforce strict authentication and authorization policies, ensuring that low privileged accounts cannot perform privileged operations.
  • Monitor logs for suspicious activity and enable alerts for unauthorized access attempts.
  • Segment the management network and consider disabling unused services to reduce surface area.

Generated by OpenCVE AI on August 21, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1.0.0.0:*:*:*:*:*:*:*

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Network-based Takeover of Oracle Enterprise Manager Base Platform
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T16:00:53.923Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61284

cve-icon Vulnrichment

Updated: 2026-08-21T15:54:24.676Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:57.810

Modified: 2026-08-26T17:36:39.173

Link: CVE-2026-61284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:00:11Z

Weaknesses