Junglewise Threat Intelligence

CVE-2026-46984: Oracle Enterprise Manager Base Platform information disclosure in Agent Next Gen

CVE-2026-46984 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Enterprise Manager Base Platform. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Enterprise Manager Base Platform, a tool used by organizations to manage and monitor their Oracle software and hardware environments. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive management data. While the attacker cannot modify or delete information, this exposure could reveal configuration details or other internal data to unauthorized parties.

Technical details

An information disclosure vulnerability exists in the Agent Next Gen component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows the attacker to gain unauthorized read access to a subset of data managed by the platform. The vulnerability is characterized by a CVSS 3.1 base score of 5.3, specifically impacting confidentiality without affecting integrity or availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats