Impact
The vulnerability lies within Oracle Enterprise Manager's Event Management component. It permits an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data, read subset data, and trigger a partial denial of service. The exploit causes significant confidentiality, integrity, and availability impacts, reflected in a CVSS 3.1 score of 8.6.
Affected Systems
Affected by Oracle, Oracle Enterprise Manager Base Platform versions 13.5 and 24.1.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score of less than 1% indicates a low probability of public exploitation. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the weakness remotely via HTTP without authentication, using the exposed Event Management API endpoints. Successful exploitation would enable the attacker to perform any data‑management operation or disrupt services, undermining data integrity and availability for the platform.
OpenCVE Enrichment