Executive brief
A vulnerability exists in the Oracle Enterprise Manager Base Platform, a centralized management solution used to monitor and manage enterprise IT environments. A high-privileged attacker could exploit this flaw to gain full control over the management platform. This could lead to a total loss of confidentiality, integrity, and availability of the management system and the infrastructure it oversees.
Technical details
This vulnerability affects the Extensibility Framework component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as an improper access control issue (CWE-284) that is easily exploitable over the network via HTTPS. While the attack requires high privileges (PR:H), a successful exploit allows for a complete takeover of the platform, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory