Impact
Vulnerability in the Application Config Console component of Oracle Enterprise Manager Base Platform allows an attacker with low privileges and network access to HTTP to bypass normal access controls and gain full control over the platform, potentially exposing confidential data, altering system configuration, and disrupting availability.
Affected Systems
Oracle Enterprise Manager Base Platform version 13.5 and 24.1 are affected, as identified by the vendor. The weakness exists in the Application Config Console component, which is reachable through standard HTTP interfaces.
Risk and Exploitability
This flaw has a CVSS base score of 8.8, indicating high severity with complete confidentiality, integrity, and availability impact. While EPSS is not available, the lack of a KEV listing does not mitigate the risk; the vulnerability can be exploited over the network by a low privileged user, potentially resulting in full takeover if no network segmentation or strict access restrictions exist. Attackers should be assumed capable of reaching the HTTP interface.
OpenCVE Enrichment