Oracle Enterprise Manager Vulnerability Exposes Sensitive Data
CVE-2026-47001

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47001?

The vulnerability in Oracle Enterprise Manager allows low privileged attackers with network access via HTTPS to exploit the Web Services Framework component, potentially leading to unauthorized modification or access to sensitive data. This could result in unauthorized updates, inserts, or deletions of accessible data. Attackers can also gain unauthorized read access to some confidential information, thereby compromising the integrity and confidentiality of the Oracle Enterprise Manager Base Platform.

Affected Version(s)

Oracle Enterprise Manager Base Platform 13.5

Oracle Enterprise Manager Base Platform 24.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.