Executive brief
A vulnerability exists in the Agent Next Gen component of Oracle Enterprise Manager, a platform used by organizations to manage and monitor their IT infrastructure. An unauthorized person could exploit this flaw over the network to view sensitive information that they should not have access to. While the attacker cannot modify data or shut down the system, the exposure of internal management data could assist in further targeted attacks.
Technical details
This vulnerability affects the Agent Next Gen component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as an information disclosure flaw that is easily exploitable by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows the attacker to gain unauthorized read access to a subset of data within the platform. The vulnerability has a CVSS 3.1 base score of 5.3, reflecting a partial impact on confidentiality with no impact on integrity or availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed