Description
Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Storage Server Management component of Oracle Enterprise Manager for Systems Infrastructure allows a low-privileged attacker who can reach the service over HTTP to compromise the system. The flaw enables the attacker to execute arbitrary actions that would normally require higher privileges, resulting in a full takeover that damages confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.8 reflects high impact across all data assets and system operation.

Affected Systems

Oracle Enterprise Manager for Systems Infrastructure versions 13.5 and 24.1 are affected. These products expose a web interface for managing storage servers; compromise would give an attacker control over the monitoring and management functions of the entire infrastructure.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. Because the attack vector is network-based over HTTP and only requires low privileged access, the exploitability is considered high. The EPSS score is 0.00479 (less than 1%) and the vulnerability is not listed in CISA’s KEV catalog, but the ease of exploitation and the breadth of impact warrant immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 06:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch disclosed in the August 2026 security alert (CSPU aug 2026).
  • Restrict HTTP access to the Enterprise Manager service to trusted IP ranges or apply firewall rules to block unauthorized inbound traffic.
  • Disable or restrict unused HTTP endpoints and enforce strict authentication and authorization controls before allowing management operations.

Generated by OpenCVE AI on August 21, 2026 at 06:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Enterprise Manager For Systems Infrastructure
Vendors & Products Oracle Corporation
Oracle Corporation oracle Enterprise Manager For Systems Infrastructure

Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover via HTTP in Oracle Enterprise Manager
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover via HTTP in Oracle Enterprise Manager
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager For Systems Infrastructure
CPEs cpe:2.3:a:oracle:enterprise_manager_for_systems_infrastructure:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_for_systems_infrastructure:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager For Systems Infrastructure
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager For Systems Infrastructure
Oracle Corporation Oracle Enterprise Manager For Systems Infrastructure
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:57:05.677Z

Reserved: 2026-08-04T22:06:34.593Z

Link: CVE-2026-70737

cve-icon Vulnrichment

Updated: 2026-08-24T19:50:34.935Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T21:17:26.440

Modified: 2026-08-25T04:18:17.040

Link: CVE-2026-70737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:32:17Z

Weaknesses