Description
Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle Database. While the vulnerability is in Oracle Enterprise Manager for Oracle Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Oracle Database accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access
Action: Patch
AI Analysis

Impact

The vulnerability resides in the Core component of Oracle Enterprise Manager for Oracle Database 24.1 and is classified as an Improper Access Control weakness (CWE-284). A low-privileged attacker with network access over HTTP can exploit an easily exploitable flaw that allows unauthorized access to critical data or full data available, with the potential to change scope to impact additional products, potentially exposing sensitive information.

Affected Systems

Oracle Enterprise Manager for Oracle Database version 24.1.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 indicates a high confidentiality impact. The EPSS score is below 1% probability at this time, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be network-based via HTTP, requiring only low privileged access, which, if a patch is not applied promptly, can lead to unauthorized data exposure.

Generated by OpenCVE AI on September 17, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Oracle Enterprise Manager 24.1 from Oracle.
  • Restrict HTTP access to the Enterprise Manager to trusted networks or IP ranges.
  • Monitor audit logs for anomalous access attempts and enforce strict role‑based access controls.

Generated by OpenCVE AI on September 17, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Low-privileged HTTP Access Enables Unauthorized Data Access in Oracle Enterprise Manager 24.1

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle Database. While the vulnerability is in Oracle Enterprise Manager for Oracle Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Oracle Database accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle enterprise Manager For Oracle Database
CPEs cpe:2.3:a:oracle:enterprise_manager_for_oracle_database:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager For Oracle Database
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Enterprise Manager For Oracle Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:59:24.109Z

Reserved: 2026-08-31T15:40:57.337Z

Link: CVE-2026-83068

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:41.873Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:15.663

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses