Executive brief
A critical vulnerability exists in Oracle Enterprise Manager's Application Performance Management (APM) tool, which is used to monitor and manage software performance. An unauthenticated attacker can remotely exploit this flaw over the network to delete or modify critical monitoring data and shut down the service entirely. This could lead to a complete loss of visibility into application health and the corruption of historical performance records.
Technical details
This vulnerability is classified as Improper Access Control (CWE-284) within the JADM and JVM Diagnostics components of Oracle Enterprise Manager's APM. It is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for the unauthorized creation, deletion, or modification of all data accessible to the APM product. Additionally, attackers can trigger a hang or a frequently repeatable crash, resulting in a complete denial of service (DoS). The vulnerability affects versions 13.5 and 24.1. Users should refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle Corporation APM - Application Performance Management 13.5, 24.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory