Impact
The Oracle Enterprise Manager Base Platform contains an access control flaw in its Event Management component that exposes a SOAP interface. A low‑privileged attacker with network access can manipulate the SOAP endpoint to create, delete, or modify critical data. The flaw allows the attacker to perform unauthorized data manipulations, leading to loss of data integrity. This is a CWE‑284 vulnerability.
Affected Systems
Vulnerable installations are Oracle Enterprise Manager Base Platform from Oracle Corporation. In particular, supported versions 13.5 and 24.1 are affected. Organizations using these releases need to verify whether the SOAP interface is exposed and whether the affected component is active.
Risk and Exploitability
The vulnerability scores a moderate CVSS 6.5 with a low exploitation probability (EPSS < 1%) and is not listed in the CISA KEV catalog. While exploitation requires network reach to the SOAP service and low privileges, the impact on data integrity is significant. The principal attack path is over the network using SOAP, so limiting network exposure, enforcing least privilege, and applying the remedy reduce the risk.
OpenCVE Enrichment