Executive brief
A critical vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage enterprise IT infrastructure. A high-privileged attacker can exploit this flaw to take complete control of the management platform. Because this tool manages other systems, a successful attack could also allow the attacker to compromise additional connected products and services across the organization.
Technical details
This vulnerability exists in the Deployment Library component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as an 'easily exploitable' flaw that allows a high-privileged attacker with network access via HTTPS to compromise the platform. The vulnerability includes a 'scope change' (Status: C in CVSS), meaning an attacker can impact components beyond the immediate security scope of the Enterprise Manager. Successful exploitation results in a complete takeover of the platform, impacting confidentiality, integrity, and availability. While specific CWE details are not provided by the vendor, the CVSS vector indicates no user interaction is required.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle and NVD publication.
- 2026-06-17: advisory: Oracle security alert published.