Sceawere

Vulnerability Detail

CVE-2026-70737UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Storage Server Management Takeover Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Enterprise Manager for Systems Infrastructure
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-18T21:17:26.440Z",
  "pubdate": "2026-08-18T21:17:26.440Z",
  "executiveSummary": "A critical security vulnerability affects the Oracle Enterprise Manager for Systems Infrastructure product, specifically within the Storage Server Management component. Supported versions 13.5 and 24.1 are susceptible to this flaw.\nThe vulnerability is classified as easily exploitable, allowing a low-privileged remote attacker with network access via the HTTP protocol to compromise the entire application. Successful exploitation leads to a complete takeover of Oracle Enterprise Manager for Systems Infrastructure, impacting confidentiality, integrity, and availability with a CVSS 3.1 Base Score of 8.8.\nThe attack vector is network-based (AV:N), requiring low attack complexity (AC:L) and low privileges (PR:L), but no user interaction (UI:N). The scope remains unchanged (S:U), yet the resulting impact on confidentiality (C:H), integrity (I:H), and availability (A:H) is total.\nOrganizations utilizing the affected software face severe risk implications, including unauthorized administrative control, data exfiltration, system manipulation, and denial of service. Immediate remediation is required to prevent unauthorized exploitation of the management infrastructure.",
  "technicalDetails": "The vulnerability resides in the Storage Server Management component of Oracle Enterprise Manager for Systems Infrastructure versions 13.5 and 24.1. The flaw enables low-privileged authenticated users to leverage network-based HTTP channels to interact with vulnerable internal routines.\nExploitation occurs via the HTTP protocol where an attacker with low-privileged network access submits crafted requests to the Storage Server Management component. Due to insufficient input validation, authorization checks, or insecure deserialization/command execution flaws inherent in the affected component's design, the application processes the malicious payload without adequate restriction.\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes an HTTP connection to the exposed Oracle Enterprise Manager interface. Second, the attacker authenticates using valid low-privileged credentials to satisfy the initial access requirement. Third, the attacker transmits a specially crafted payload targeting the Storage Server Management subsystem. Fourth, the vulnerable component processes the request, bypassing security controls due to flawed privilege validation or logic execution. Finally, the execution of the payload grants the attacker elevated privileges or direct administrative control over the underlying architecture.\nThe post-exploitation impact includes the total takeover of Oracle Enterprise Manager for Systems Infrastructure. Because the application manages underlying infrastructure and storage servers, a complete system compromise allows the attacker to pivot deeper into the network, manipulate storage resources, intercept confidential data, corrupt system integrity, and disrupt critical availability."
}
CVE-2026-70737: Storage Server Management Takeover Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere