Executive brief
A critical vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage enterprise IT infrastructure. A low-privileged user can exploit this flaw over the network to take full control of the management platform. Because this tool manages other systems, a successful attack could allow an intruder to compromise additional connected products and services across the organization.
Technical details
This vulnerability is classified as Improper Access Control (CWE-284) within the Target Management component of Oracle Enterprise Manager Base Platform. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (CVSS Scope: Changed), meaning a successful exploit allows the attacker to move beyond the security boundaries of the Enterprise Manager and impact other products managed by the platform. Successful exploitation can result in a complete takeover of the affected system, compromising confidentiality, integrity, and availability. Affected versions include 13.5 and 24.1.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD entry published