Executive brief
Oracle Enterprise Manager is a management platform used to monitor and manage Oracle software and hardware across an organization. A critical vulnerability in its Metadata Plugin component could allow an unauthenticated attacker to completely take over the system if a legitimate user interacts with a malicious link or site. This could lead to a total loss of confidentiality and control over the managed infrastructure, potentially impacting other connected systems.
Technical details
A vulnerability in the Metadata Plugin component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) is classified as a Cross-Site Scripting (XSS) or similar web-based injection flaw (CWE-79). The vulnerability is easily exploitable via HTTP by an unauthenticated remote attacker. While the attack requires human interaction (UI:R), the 'Scope Change' (S:C) designation indicates that a successful exploit allows the attacker to move beyond the privileges of the affected component to impact other products or the underlying platform. Successful exploitation can result in a complete takeover of the Oracle Enterprise Manager Base Platform, affecting confidentiality, integrity, and availability.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date