Oracle Enterprise Manager Base Platform vulnerabilities
141 known vulnerabilities affecting oracle/enterprise_manager_base_platform.
Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL17HIGH57MEDIUM66LOW1
Vulnerabilities
Page 5 of 8
CVE-2018-1257P3MEDIUMCVSS 6.5v12.1.0.5.0v13.2.0.0.0+1 more2018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2020-2609P3MEDIUMCVSS 6.3v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2609 [MEDIUM] CVE-2020-2609: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful a
nvd
CVE-2020-24977P4MEDIUMCVSS 6.5v13.4.0.0v13.5.0.02020-09-04
CVE-2020-24977 [MEDIUM] CWE-125 CVE-2020-24977: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesIntern
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1v12.1.0.5v13.3.0.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2019-2897P3MEDIUMCVSS 6.4v13.4.0.02019-10-16
CVE-2019-2897 [MEDIUM] CVE-2019-2897: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2018-1656P4MEDIUMCVSS 6.5v13.2.0.0.0v13.3.0.0.02018-08-20
CVE-2018-1656 [MEDIUM] CWE-22 CVE-2018-1656: The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Techn
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.
nvd
CVE-2026-46986P4MEDIUMCVSS 5.3v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46986 [MEDIUM] CWE-284 CVE-2026-46986: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks
nvd
CVE-2026-46984P4MEDIUMCVSS 5.3v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46984 [MEDIUM] CWE-284 CVE-2026-46984: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks
nvd
CVE-2018-0735P4MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2018-10-29
CVE-2018-0735 [MEDIUM] CWE-327 CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attac
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
nvd
CVE-2018-2750P4HIGHCVSS 7.1v12.1.0.52018-04-19
CVE-2018-2750 [HIGH] CVE-2018-2750: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Product
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: UI Framework). The supported version that is affected is 12.1.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks require huma
nvd
CVE-2019-10247P4MEDIUMCVSS 5.3v13.2v13.32019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2026-47002P4MEDIUMCVSS 6.1v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-47002 [MEDIUM] CWE-601 CVE-2026-47002: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks r
nvd
CVE-2026-47001P4MEDIUMCVSS 5.4v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-47001 [MEDIUM] CWE-284 CVE-2026-47001: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Web Services Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful
nvd
CVE-2026-46985P4MEDIUMCVSS 5.3v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46985 [MEDIUM] CWE-284 CVE-2026-46985: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks
nvd
CVE-2018-11039P4MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2018-06-25
CVE-2018-11039 [MEDIUM] CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupport
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filt
nvd
CVE-2019-10246P4MEDIUMCVSS 5.3v13.2v13.32019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2020-2626P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2626 [MEDIUM] CVE-2020-2626: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Cloud Control Manager - OMS). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful a
nvd
CVE-2020-2628P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2628 [MEDIUM] CVE-2020-2628: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of th
nvd
CVE-2020-1954P4MEDIUMCVSS 5.3v13.2.1.02020-04-01
CVE-2020-1954 [MEDIUM] CVE-2020-1954: Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind th
nvd
CVE-2020-2608P4MEDIUMCVSS 6.0v13.2.0.0v13.3.0.02020-01-15
CVE-2020-2608 [MEDIUM] CVE-2020-2608: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Repository). Supported versions that are affected are 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerabilit
nvd