Impact
Oracle Application Testing Suite 13.3.0.1 contains a vulnerability that is easily exploitable by an unauthenticated attacker with network access via TCP. The flaw, identified as CWE‑284 (Improper Access Control), allows the attacker to bypass authentication and gain unauthorized access to critical data or the entirety of data the application can deliver. The vulnerability has a CVSS 3.1 base score of 7.5, indicating a high confidentiality impact with no effect on integrity or availability.
Affected Systems
Affected system is Oracle Corporation’s Oracle Application Testing Suite, specifically version 13.3.0.1. This is the only version noted in the CNA data as vulnerable.
Risk and Exploitability
The risk is assessed as high due to the confidentiality impact and the fact that it is exploitable remotely with no authentication required. The EPSS score of less than 1 % indicates a very low probability of exploitation as of the current data; however, the vulnerability is not listed in CISA’s KEV catalog, meaning there has been no confirmed exploitation reported yet. Likely attack vectors involve remote TCP traffic directed at unprotected services within the application, and the attack can be carried out without special privileges or elevated permissions.
OpenCVE Enrichment