Executive brief
A vulnerability in the Enterprise Config Management component of Oracle Enterprise Manager could allow an attacker to take full control of the platform. Oracle Enterprise Manager is used by organizations to manage and monitor their entire IT infrastructure, including databases and applications. An exploit could lead to a total loss of confidentiality and service availability, potentially impacting all systems managed by the platform.
Technical details
A vulnerability exists in the Enterprise Config Management component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1). The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. While the specific vulnerability class (e.g., injection or broken access control) is not explicitly named in the advisory, the impact is a complete compromise of the platform's confidentiality, integrity, and availability. Successful exploitation allows for a total takeover of the Oracle Enterprise Manager Base Platform. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory