Impact
Oracle Enterprise Manager Base Platform hosts a local vulnerability that can be triggered by a low‑privileged attacker who is already authenticated to the host. The bug is described as difficult to exploit, yet when successful it allows the attacker to compromise the platform and gain unauthorized access to all data it manages. The impact is limited to confidentiality; integrity and availability remain unaffected.
Affected Systems
The affected products are Oracle Enterprise Manager Base Platform version 13.5 and 24.1 from Oracle Corporation. No other products are listed as affected in this entry.
Risk and Exploitability
The CVSS v3.1 Base Score of 5.6 indicates a moderate severity for confidentiality. The EPSS score is 0.00117 (indicating an extremely low probability of exploitation) and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local (AV:L) and requires an existing host logon with low privileges (PR:L). Because the scope change (S:C) is present, compromise of the base platform may also affect dependent Oracle applications that rely on the compromised component. Overall, the risk is moderate but the potential for data exposure justifies timely remediation.
OpenCVE Enrichment