Executive brief
Oracle Enterprise Manager for Fusion Middleware is a centralized management platform for Oracle Fusion applications and middleware infrastructure. An unauthenticated attacker can remotely exploit a vulnerability in the Metrics component to gain complete control of the system, potentially leading to unauthorized access to sensitive data, system compromise, and operational disruption across managed Fusion environments.
Technical details
This is an easily exploitable vulnerability in the Metrics component of Oracle Enterprise Manager for Fusion Middleware that requires no authentication. The flaw is remotely reachable via HTTP and allows an unauthenticated attacker on the network to achieve complete system compromise. The vulnerability results in high impact across confidentiality, integrity, and availability—meaning attackers can read sensitive data, modify configurations, and disrupt service. Patches are expected from Oracle for affected versions 13.5 and 24.1.
Affected products
- Oracle Enterprise Manager for Fusion Middleware 13.5, 24.1
Timeline
- 2026-09-15: disclosed