---
id: CVE-2026-70737
title: >-
  Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure
  product of Oracle Enterprise Manager (component: Storage Server Management)
summary: >-
  Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure
  product of Oracle Enterprise Manager (component: Storage Server Management). 
  Supported versions that are affected are 13.5 and  24.1. Easily exploitable
  vulnerabi…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: oracle
product: enterprise_manager_for_systems_infrastructure
affected:
  - enterprise_manager_for_systems_infrastructure = 13.5
  - enterprise_manager_for_systems_infrastructure = 24.1
published: '2026-08-18'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T20:14:41.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-70737'
references:
  - url: 'https://www.oracle.com/security-alerts/cspuaug2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-24T00:00:00+00:00'
ingestedAt: '2026-09-13T14:53:22.714Z'
epss: 0.00432
epssPercentile: 0.3707
---

## Overview

Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

## Affected

- `enterprise_manager_for_systems_infrastructure = 13.5`
- `enterprise_manager_for_systems_infrastructure = 24.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
