{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Oracle heeft meerdere kwetsbaarheden verholpen in Oracle Enterprise Manager Base Platform versies 13.5 en 24.1.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "De kwetsbaarheden in Oracle Enterprise Manager Base Platform stellen aanvallers in staat om via netwerktoegang over HTTPS of HTTP zonder authenticatie of met lage privileges ongeautoriseerde lees-, schrijf-, creatie-, verwijdering- en wijzigingsacties op gevoelige data uit te voeren. Sommige kwetsbaarheden maken het mogelijk om volledige systeemcompromittering te bereiken, waaronder het uitvoeren van willekeurige code en het overnemen van het systeem. Andere kwetsbaarheden kunnen leiden tot gedeeltelijke denial-of-service condities. De kwetsbaarheden zijn aanwezig in verschillende componenten van het platform, zoals Agent Next Gen, Metadata Plugin en UI Framework. Exploitatie kan vereisen dat de aanvaller netwerktoegang heeft en in enkele gevallen gebruikersinteractie. De kwetsbaarheden maken gebruik van onvoldoende toegangscontrole en onjuiste beveiligingsmaatregelen binnen het platform.",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Oracle heeft updates uitgebracht om de kwetsbaarheden in Oracle Enterprise Manager Base Platform te verhelpen. Zie bijgevoegde referenties voor meer informatie.",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Improper Privilege Management",
                "title": "CWE-269"
            },
            {
                "category": "general",
                "text": "Improper Certificate Validation",
                "title": "CWE-295"
            },
            {
                "category": "general",
                "text": "Improper Validation of Certificate with Host Mismatch",
                "title": "CWE-297"
            },
            {
                "category": "general",
                "text": "Deserialization of Untrusted Data",
                "title": "CWE-502"
            },
            {
                "category": "general",
                "text": "Improper Restriction of XML External Entity Reference",
                "title": "CWE-611"
            },
            {
                "category": "general",
                "text": "Allocation of Resources Without Limits or Throttling",
                "title": "CWE-770"
            },
            {
                "category": "general",
                "text": "OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities",
                "title": "CWE-937"
            },
            {
                "category": "general",
                "text": "OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities",
                "title": "CWE-1035"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "references": [
            {
                "category": "external",
                "summary": "Reference",
                "url": "https://www.oracle.com/security-alerts/cpujul2026.html"
            },
            {
                "category": "external",
                "summary": "Reference",
                "url": "https://www.oracle.com/security-alerts/cpujul2026verbose.html"
            }
        ],
        "title": "Kwetsbaarheden verholpen in Oracle Enterprise Manager",
        "tracking": {
            "current_release_date": "2026-07-22T15:19:16.529859Z",
            "generator": {
                "date": "2025-08-04T16:30:00Z",
                "engine": {
                    "name": "V.A.",
                    "version": "1.3"
                }
            },
            "id": "NCSC-2026-0257",
            "initial_release_date": "2026-07-22T15:19:16.529859Z",
            "revision_history": [
                {
                    "date": "2026-07-22T15:19:16.529859Z",
                    "number": "1.0.0",
                    "summary": "Initiele versie"
                }
            ],
            "status": "final",
            "version": "1.0.0"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-1"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Enterprise Manager"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-2"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Enterprise Manager Base Platform"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/*",
                                "product": {
                                    "name": "vers:unknown/*",
                                    "product_id": "CSAFPID-3"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Enterprise Manager for Fusion Middleware"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2014-3643",
            "cwe": {
                "id": "CWE-611",
                "name": "Improper Restriction of XML External Entity Reference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Restriction of XML External Entity Reference",
                    "title": "CWE-611"
                },
                {
                    "category": "description",
                    "text": "Jersey's SAX parser contains an XML external entity (XXE) vulnerability due to not disabling parameter entities, enabling remote attackers to access sensitive information via crafted XML data.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2014-3643 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2014/cve-2014-3643.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2014-3643"
        },
        {
            "cve": "CVE-2020-9547",
            "cwe": {
                "id": "CWE-502",
                "name": "Deserialization of Untrusted Data"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Deserialization of Untrusted Data",
                    "title": "CWE-502"
                },
                {
                    "category": "description",
                    "text": "Multiple vulnerabilities in FasterXML jackson-databind versions prior to 2.9.10.4 and Oracle Fusion Middleware allow remote code execution, data confidentiality breaches, and system availability impacts through improper handling of serialization gadgets and typing.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2020-9547 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2020/cve-2020-9547.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2020-9547"
        },
        {
            "cve": "CVE-2025-8916",
            "cwe": {
                "id": "CWE-770",
                "name": "Allocation of Resources Without Limits or Throttling"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Allocation of Resources Without Limits or Throttling",
                    "title": "CWE-770"
                },
                {
                    "category": "description",
                    "text": "Multiple vulnerabilities including excessive resource allocation, denial of service, SQL injection, and information disclosure affect Bouncy Castle Java libraries, Oracle Communications, Oracle Siebel CRM, Oracle Fusion Middleware, HPE Telco Service Activator, and various NetApp products.",
                    "title": "Summary"
                },
                {
                    "category": "general",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/S:P/R:U/RE:M/U:Amber",
                    "title": "CVSSV4"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-8916 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-8916.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2025-8916"
        },
        {
            "cve": "CVE-2025-68161",
            "cwe": {
                "id": "CWE-297",
                "name": "Improper Validation of Certificate with Host Mismatch"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Validation of Certificate with Host Mismatch",
                    "title": "CWE-297"
                },
                {
                    "category": "other",
                    "text": "Improper Certificate Validation",
                    "title": "CWE-295"
                },
                {
                    "category": "description",
                    "text": "Apache Log4j Core versions 2.0-beta9 through 2.25.2 have a critical vulnerability in the Socket Appender due to missing TLS hostname verification, enabling man-in-the-middle attacks, affecting multiple vendors including Oracle, IBM, NetApp, and SAP.",
                    "title": "Summary"
                },
                {
                    "category": "general",
                    "text": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2025-68161 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-68161.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2025-68161"
        },
        {
            "cve": "CVE-2026-46984",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform (Agent Next Gen) versions 13.5 and 24.1 allows unauthenticated attackers with HTTPS network access to gain unauthorized read access to certain data, rated CVSS 3.1 score 5.3.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46984 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46984.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46984"
        },
        {
            "cve": "CVE-2026-46985",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform (Agent Next Gen) versions 13.5 and 24.1 allows unauthenticated attackers with HTTPS network access to gain unauthorized read access to certain data, rated CVSS 3.1 score 5.3.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46985 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46985.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46985"
        },
        {
            "cve": "CVE-2026-46986",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform (Agent Next Gen) versions 13.5 and 24.1 allows unauthenticated attackers with HTTPS network access to gain unauthorized read access to certain data, rated CVSS 3.1 score 5.3.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46986 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46986.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46986"
        },
        {
            "cve": "CVE-2026-46987",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a low-privileged attacker with HTTPS network access to gain unauthorized access to critical data, rated CVSS 3.1 base score 7.7.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46987 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46987.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46987"
        },
        {
            "cve": "CVE-2026-46988",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a highly privileged attacker with HTTPS network access to potentially take control of the system, with a CVSS 3.1 score of 7.2.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46988 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46988.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46988"
        },
        {
            "cve": "CVE-2026-46989",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 enables low-privileged attackers with HTTPS network access to gain unauthorized data access, modify data, and cause partial denial of service, rated CVSS 9.1.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46989 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46989.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L",
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46989"
        },
        {
            "cve": "CVE-2026-46990",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows unauthenticated network attackers via HTTP to perform unauthorized data modifications, read access, and partial denial of service, rated CVSS 3.1 score 7.3.",
                    "title": "Summary"
                },
                {
                    "category": "general",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                    "title": "CVSSV4"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46990 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46990.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46990"
        },
        {
            "cve": "CVE-2026-46991",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows low-privileged attackers with logon access to perform unauthorized read and write operations, with a CVSS 3.1 base score of 4.4.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46991 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46991.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46991"
        },
        {
            "cve": "CVE-2026-46992",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a low-privileged attacker with HTTPS network access to fully compromise the system, rated with a CVSS 3.1 base score of 8.8.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46992 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46992.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46992"
        },
        {
            "cve": "CVE-2026-46993",
            "notes": [
                {
                    "category": "description",
                    "text": "A high-severity vulnerability in Oracle Enterprise Manager Base Platform (Agent Next Gen) versions 13.5 and 24.1 allows low-privileged attackers with HTTPS network access to create, delete, or modify critical data unauthorizedly.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46993 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46993.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46993"
        },
        {
            "cve": "CVE-2026-46994",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical unauthenticated remote code execution vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 via HTTPS has a CVSS 3.1 score of 9.8, severely impacting confidentiality, integrity, and availability.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46994 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46994.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46994"
        },
        {
            "cve": "CVE-2026-46995",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a low-privileged attacker with HTTPS network access to fully compromise the system, with a CVSS 3.1 base score of 8.8.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46995 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46995.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46995"
        },
        {
            "cve": "CVE-2026-46996",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform (Metadata Plugin) versions 13.5 and 24.1 allows low-privileged attackers with HTTPS network access to manipulate critical data, with a CVSS 3.1 score of 7.1 indicating significant confidentiality and integrity impact.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46996 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46996.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46996"
        },
        {
            "cve": "CVE-2026-46997",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform (Metadata Plugin) versions 13.5 and 24.1 allows a low-privileged attacker with HTTPS network access to modify critical data, with a CVSS 3.1 base score of 6.5 indicating significant integrity impact.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46997 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46997.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46997"
        },
        {
            "cve": "CVE-2026-46998",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows unauthenticated network attackers via HTTPS to potentially take control of the platform, with a CVSS score of 8.8 impacting confidentiality, integrity, and availability.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46998 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46998.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46998"
        },
        {
            "cve": "CVE-2026-46999",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows unauthenticated attackers with HTTPS network access to modify or delete critical data, read some data, or cause partial denial of service, rated CVSS 7.0.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-46999 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-46999.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L",
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-46999"
        },
        {
            "cve": "CVE-2026-47000",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform 24.1 allows a low-privileged attacker with HTTPS network access and user interaction to perform unauthorized data modifications, rated with a CVSS 3.1 base score of 3.5 for integrity impact.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-47000 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-47000.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
                        "baseScore": 3.5,
                        "baseSeverity": "LOW"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-47000"
        },
        {
            "cve": "CVE-2026-47001",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a low-privileged attacker with HTTPS network access to gain unauthorized read and write access to certain data, rated CVSS 3.1 score 5.4.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-47001 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-47001.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-47001"
        },
        {
            "cve": "CVE-2026-47002",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows unauthenticated attackers with HTTPS network access to perform unauthorized read and write operations, with a CVSS 3.1 base score of 6.1.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-47002 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-47002.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-47002"
        },
        {
            "cve": "CVE-2026-47003",
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability in Oracle Enterprise Manager Base Platform UI Framework versions 13.5 and 24.1 allows unauthenticated attackers with HTTPS network access to potentially gain unauthorized access to critical data, rated CVSS 3.1 score 5.9.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-47003 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-47003.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-47003"
        },
        {
            "cve": "CVE-2026-47004",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a low-privileged attacker with HTTPS network access to fully compromise the system, with a CVSS 3.1 base score of 8.8.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-47004 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-47004.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-47004"
        },
        {
            "cve": "CVE-2026-47005",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a highly privileged attacker with HTTPS network access to potentially take control, rated CVSS 3.1 score 7.2 for high impact on confidentiality, integrity, and availability.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-47005 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-47005.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-47005"
        },
        {
            "cve": "CVE-2026-47006",
            "notes": [
                {
                    "category": "description",
                    "text": "A critical vulnerability in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 allows a highly privileged attacker with HTTPS network access to potentially take control, rated CVSS 3.1 score 7.2 for high impact on confidentiality, integrity, and availability.",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1",
                    "CSAFPID-2",
                    "CSAFPID-3"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2026-47006 | NCSC-NL Website",
                    "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2026/cve-2026-47006.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1",
                        "CSAFPID-2",
                        "CSAFPID-3"
                    ]
                }
            ],
            "title": "CVE-2026-47006"
        }
    ]
}