Impact
A vulnerability in the Storage Server Management component of Oracle Enterprise Manager for Systems Infrastructure allows a low-privileged attacker who can reach the service over HTTP to compromise the system. The flaw enables the attacker to execute arbitrary actions that would normally require higher privileges, resulting in a full takeover that damages confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.8 reflects high impact across all data assets and system operation.
Affected Systems
Oracle Enterprise Manager for Systems Infrastructure versions 13.5 and 24.1 are affected. These products expose a web interface for managing storage servers; compromise would give an attacker control over the monitoring and management functions of the entire infrastructure.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. Because the attack vector is network-based over HTTP and only requires low privileged access, the exploitability is considered high. The EPSS score is 0.00479 (less than 1%) and the vulnerability is not listed in CISA’s KEV catalog, but the ease of exploitation and the breadth of impact warrant immediate attention.
OpenCVE Enrichment