Executive brief
A security vulnerability exists in Oracle Enterprise Manager, a centralized management platform used to monitor and manage corporate IT infrastructure. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. Because this platform manages other systems, a successful attack could potentially allow the intruder to access information across multiple connected products.
Technical details
This vulnerability resides in the Application Service Level Mgmt component of the Oracle Enterprise Manager Base Platform. It is classified as an information disclosure flaw that allows a low-privileged attacker with network access via HTTPS to compromise the system. The vulnerability is notable for its 'Scope Change' (S:C) designation, meaning an exploit can impact resources beyond the security scope of the Enterprise Manager itself. Successful exploitation results in high confidentiality impacts, potentially granting access to all data accessible by the platform. Affected versions include 13.5 and 24.1. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.