CVE-2026-46858
Awaiting Analysis Awaiting Analysis - Queue
Unauthenticated DoS in Oracle Enterprise Manager APM

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application Performance Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all APM - Application Performance Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of APM - Application Performance Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
oracle application_performance_management 13.5
oracle application_performance_management 24.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the APM - Application Performance Management product of Oracle Enterprise Manager, specifically in the JADM and JVM Diagnostics components.

It affects supported versions 13.5 and 24.1 and allows an unauthenticated attacker with network access via HTTP to exploit the system.

The attacker can compromise the APM system by unauthorized creation, deletion, or modification of critical data or any accessible data within APM.

Additionally, the attacker can cause the system to hang or repeatedly crash, resulting in a complete denial of service (DoS).

Impact Analysis

This vulnerability can have serious impacts including unauthorized modification or deletion of critical data within the APM system.

It can also lead to a complete denial of service by causing the system to hang or crash repeatedly.

Because the vulnerability can be exploited without authentication and remotely via HTTP, it poses a high risk to the integrity and availability of the affected system.

Compliance Impact

The vulnerability allows an unauthenticated attacker with network access to compromise the Application Performance Management product, resulting in unauthorized creation, deletion, or modification of critical data and the ability to cause denial of service. Such unauthorized access and data integrity issues could potentially impact compliance with standards and regulations that require protection of data integrity and availability, such as GDPR and HIPAA.

However, the provided information does not explicitly mention the impact on compliance with specific standards or regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart