Impact
The vulnerability resides in the Agent Next Gen component of Oracle Enterprise Manager Base Platform and allows a low privileged attacker who can logon to the infrastructure where the platform runs to execute arbitrary actions. Successful exploitation results in a complete takeover, compromising confidentiality, integrity, and availability of the platform as indicated by the CVSS 3.1 score of 7.8.
Affected Systems
Oracle Corporation’s Oracle Enterprise Manager Base Platform, specifically versions 13.5 and 24.1 are affected. Any deployment of these versions running the Agent Next Gen component is exposed.
Risk and Exploitability
The CVSS base score reflects a moderate-to-high severity with a local attack vector requiring authentication and low privileged actions. While the EPSS score is not available and the vulnerability is not currently listed in CISA’s KEV catalog, the ease of exploitation once an attacker has logon access creates a significant risk, especially in environments where privileged accounts are not strictly controlled.
OpenCVE Enrichment