Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Immediate Patch
AI Analysis

Impact

The Oracle Enterprise Manager Base Platform contains an access control flaw in its Event Management component that exposes a SOAP interface. A low‑privileged attacker with network access can manipulate the SOAP endpoint to create, delete, or modify critical data. The flaw allows the attacker to perform unauthorized data manipulations, leading to loss of data integrity. This is a CWE‑284 vulnerability.

Affected Systems

Vulnerable installations are Oracle Enterprise Manager Base Platform from Oracle Corporation. In particular, supported versions 13.5 and 24.1 are affected. Organizations using these releases need to verify whether the SOAP interface is exposed and whether the affected component is active.

Risk and Exploitability

The vulnerability scores a moderate CVSS 6.5 with a low exploitation probability (EPSS < 1%) and is not listed in the CISA KEV catalog. While exploitation requires network reach to the SOAP service and low privileges, the impact on data integrity is significant. The principal attack path is over the network using SOAP, so limiting network exposure, enforcing least privilege, and applying the remedy reduce the risk.

Generated by OpenCVE AI on September 17, 2026 at 06:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued security patch that addresses the access control flaw in the Oracle Enterprise Manager Base Platform.
  • Restrict or disable the SOAP interface to trusted hosts only, or place a firewall rule limiting inbound SOAP traffic.
  • Configure least‑privilege roles for users that may interact with the Event Management component to prevent unauthorized data manipulation.

Generated by OpenCVE AI on September 17, 2026 at 06:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via SOAP in Oracle Enterprise Manager Base Platform

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:31:06.197Z

Reserved: 2026-07-14T14:54:48.743Z

Link: CVE-2026-62597

cve-icon Vulnrichment

Updated: 2026-09-16T15:08:01.355Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:35.293

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-62597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:30:09Z

Weaknesses