Impact
The vulnerability is an authentication bypass in the Metrics component of Oracle Enterprise Manager for Fusion Middleware that enables an unauthenticated attacker with network access over HTTP to take full control of the system. Successful exploitation results in remote code execution and full compromise of confidentiality, integrity, and availability. The flaw is reflected by the high CVSS 9.8 score, indicating a severe impact if exploited.
Affected Systems
Both version 13.5 and 24.1 of Oracle Enterprise Manager for Fusion flaw is specific to the Enterprise Manager product as distributed by Oracle.
Risk and Exploitability
The CVSS v3.1 Base Score is 9.8, with no user interaction and low attack complexity required. The EPSS score is below 1%, indicating a low probability of widespread exploitation, but the vulnerability is listed outside the CISA KEV catalog. The attack vector is inferred to be remote HTTP traffic, and the lack of authentication credentials is a prerequisite for success.
OpenCVE Enrichment