CVE-2026-47000: CSRF
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Enterprise Manager Base Platform (Security Framework)to a version that resolves this vulnerability.Fixed in 24.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47000?
The severity of CVE-2026-47000 is rated low, with a CVSS score of 3.5.
How do I fix CVE-2026-47000?
To address CVE-2026-47000, ensure that you are running the latest version of Oracle Enterprise Manager Base Platform.
What type of vulnerability is CVE-2026-47000?
CVE-2026-47000 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2026-47000?
The vulnerability affects users of Oracle Enterprise Manager Base Platform version 24.1.
Can CVE-2026-47000 be exploited remotely?
Yes, CVE-2026-47000 can be exploited by low privileged attackers with network access via HTTPS.