Junglewise Threat Intelligence

CVE-2026-62597: Oracle Enterprise Manager Base Platform integrity violation in Event Management

CVE-2026-62597 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

Oracle Enterprise Manager Base Platform is a management tool used to monitor and control Oracle infrastructure and applications. A vulnerability in its Event Management component allows a low-privileged attacker with network access to create, delete, or modify critical data without authorization, potentially compromising the integrity of monitoring and alerting systems across the enterprise.

Technical details

This vulnerability exists in the Event Management component of Oracle Enterprise Manager Base Platform and is exploitable via SOAP protocol. A low-privileged attacker with network access can exploit this flaw to achieve unauthorized modification of critical data. The vulnerability requires user authentication (low privilege level) but does not require user interaction. Successful exploitation results in integrity impacts, allowing unauthorized data manipulation across the platform. Affected versions are 13.5 and 24.1; patch availability should be confirmed through Oracle's security advisories.

Affected products

  • Oracle Enterprise Manager Base Platform 13.5, 24.1

Timeline

  • 2026-09-15: disclosed

References

Related threats