Executive brief
A critical vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage enterprise IT infrastructure. A user with low-level access can exploit this flaw over the network to take full control of the management platform. This could lead to a total loss of confidentiality and service availability, potentially impacting other connected systems across the organization.
Technical details
A vulnerability classified as Improper Privilege Management (CWE-269) exists in the Metadata Plugin component of Oracle Enterprise Manager Base Platform. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Because the vulnerability involves a scope change (CVSS S:C), a successful exploit allows an attacker to compromise not only the base platform but potentially impact additional integrated products. This can result in a complete takeover of the Oracle Enterprise Manager environment, affecting confidentiality, integrity, and availability. Affected versions include 13.5 and 24.1.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory