Executive brief
A vulnerability exists in the Oracle Enterprise Manager Base Platform, a tool used by organizations to manage and monitor their IT infrastructure. A low-privileged attacker could exploit this flaw to gain unauthorized access to sensitive data or modify critical system information. This could lead to a significant breach of confidentiality and data integrity across the managed environment.
Technical details
This vulnerability affects the Agent Next Gen component of Oracle Enterprise Manager Base Platform versions 13.5 and 24.1. It is classified as a high-severity issue with a CVSS score of 8.2, primarily due to a scope change (S:C) that allows an attacker to impact products beyond the base platform. The attack requires low privileges and network access via HTTPS, though it is characterized as difficult to exploit (AC:H). An attacker can achieve full unauthorized access to or modification of all accessible data within the platform. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory