Vulnerability in Oracle Enterprise Manager Base Platform by Oracle
CVE-2026-46997

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-46997?

A security vulnerability in Oracle Enterprise Manager Base Platform's Metadata Plugin allows a low privileged attacker to gain unauthorized access to sensitive data. Exploiting this vulnerability via HTTPS can lead to the unauthorized creation, deletion, or modification of critical data within the affected products, impacting the overall integrity of the system. The vulnerability highlights the need for vigilance and prompt action to secure affected versions against potential threats.

Affected Version(s)

Oracle Enterprise Manager Base Platform 13.5

Oracle Enterprise Manager Base Platform 24.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.