Impact
The vulnerability resides in the Core component of Oracle Enterprise Manager for Oracle Database 24.1 and is classified as an Improper Access Control weakness (CWE-284). A low-privileged attacker with network access over HTTP can exploit an easily exploitable flaw that allows unauthorized access to critical data or full data available, with the potential to change scope to impact additional products, potentially exposing sensitive information.
Affected Systems
Oracle Enterprise Manager for Oracle Database version 24.1.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 indicates a high confidentiality impact. The EPSS score is below 1% probability at this time, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be network-based via HTTP, requiring only low privileged access, which, if a patch is not applied promptly, can lead to unauthorized data exposure.
OpenCVE Enrichment