Executive brief
A vulnerability exists in the Oracle Enterprise Manager Base Platform, a tool used by organizations to manage and monitor their Oracle software and hardware environments. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain sensitive management data. This could lead to unauthorized changes in system configurations or the exposure of internal operational information.
Technical details
A vulnerability in the Web Services Framework component of Oracle Enterprise Manager Base Platform (versions 13.5 and 24.1) allows for unauthorized data access and modification. The flaw is categorized as easily exploitable and requires an attacker to have low-level privileges and network access via HTTPS. Successful exploitation enables an attacker to perform unauthorized update, insert, or delete operations on a subset of accessible data, as well as unauthorized read access to specific data sets. The vulnerability has been assigned a CVSS 3.1 base score of 5.4, reflecting moderate impacts on confidentiality and integrity without affecting availability.
Affected products
- Oracle Enterprise Manager Base Platform 13.5, 24.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published in Oracle Critical Patch Update Advisory - July 2026