Vulnerability in Oracle Enterprise Manager Base Platform Host Management
CVE-2024-21067
8.8HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 16 April 2024
Summary
A vulnerability has been identified in the Oracle Enterprise Manager Base Platform within the Host Management component. This flaw affects version 13.5.0.0 and allows low privileged attackers, who have access to the underlying infrastructure, to compromise the functionalities of the Oracle Enterprise Manager Base Platform. While the vulnerability is contained within this specific product, it poses a risk of significantly affecting additional products within the environment. Successful exploitation can lead to the takeover of the Oracle Enterprise Manager Base Platform, potentially impacting confidentiality, integrity, and availability of the affected systems.
Affected Version(s)
Enterprise Manager Base Platform 13.5.0.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published