Executive brief
A vulnerability exists in Oracle Enterprise Manager, a centralized platform used by businesses to manage and monitor their IT infrastructure. An attacker can exploit this flaw over the network without needing any login credentials. A successful attack could allow someone to crash the management system, causing a service outage, or modify sensitive data within the platform.
Technical details
A vulnerability in the Agent Next Gen component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows for remote exploitation via HTTPS. The flaw is categorized under CWE-400 (Uncontrolled Resource Consumption), indicating it can be used to exhaust system resources. An unauthenticated attacker can trigger a hang or a repeatable crash, leading to a complete denial-of-service (DoS). Additionally, the vulnerability permits unauthorized integrity impacts, allowing attackers to update, insert, or delete certain data within the platform. The attack requires no user interaction and has a low complexity for exploitation.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published