Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Enterprise Manager Base Platform hosts a local vulnerability that can be triggered by a low‑privileged attacker who is already authenticated to the host. The bug is described as difficult to exploit, yet when successful it allows the attacker to compromise the platform and gain unauthorized access to all data it manages. The impact is limited to confidentiality; integrity and availability remain unaffected.

Affected Systems

The affected products are Oracle Enterprise Manager Base Platform version 13.5 and 24.1 from Oracle Corporation. No other products are listed as affected in this entry.

Risk and Exploitability

The CVSS v3.1 Base Score of 5.6 indicates a moderate severity for confidentiality. The EPSS score is 0.00117 (indicating an extremely low probability of exploitation) and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local (AV:L) and requires an existing host logon with low privileges (PR:L). Because the scope change (S:C) is present, compromise of the base platform may also affect dependent Oracle applications that rely on the compromised component. Overall, the risk is moderate but the potential for data exposure justifies timely remediation.

Generated by OpenCVE AI on August 21, 2026 at 12:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Oracle Enterprise Manager Base Platform 13.5 or 24.1 as released.
  • If a patch is not yet available, restrict the application to trusted network segments and disable unnecessary local user accounts.
  • Enforce least privilege by auditing and removing any non‑administrator accounts with elevated rights.

Generated by OpenCVE AI on August 21, 2026 at 12:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1.0.0.0:*:*:*:*:*:*:*

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged Local Attack Allows Confidential Data Exposure in Oracle Enterprise Manager Base Platform
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T16:08:58.002Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61298

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:58.757

Modified: 2026-08-26T17:37:17.913

Link: CVE-2026-61298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control