Executive brief
Oracle Enterprise Manager for Systems Infrastructure is a suite for managing enterprise infrastructure and storage. A low-privileged attacker with network access can exploit a vulnerability in the Storage Server Management component to gain complete control over the system, compromising confidentiality, integrity, and availability of the management infrastructure and any systems it controls.
Technical details
The vulnerability is an easily exploitable flaw in the Storage Server Management component of Oracle Enterprise Manager for Systems Infrastructure. It requires only low-level privileges and network access via HTTP to trigger—no complex exploitation or user interaction needed. A successful attack grants full compromise of the affected system, including unauthorized access to sensitive data and the ability to modify or disable critical storage management functions. The vulnerability affects versions 13.5 and 24.1; patches from Oracle should be consulted for remediation.
Affected products
- Oracle Enterprise Manager for Systems Infrastructure 13.5, 24.1
Timeline
- 2026-08-18: disclosed