Impact
The vulnerability allows an unauthenticated attacker with network access to use TCP to take control of Oracle Application Testing Suite. It is described as easily exploitable and results in a total takeover, impacting the confidentiality, integrity, and availability of the system. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and a base score of 9.8 reflect the severe nature of the flaw.
Affected Systems
Oracle Corporation’s Oracle Application Testing Suite version 13.3.0.1 is affected. No other versions or products were listed.
Risk and Exploitability
With a CVSS score of 9.8 the flaw is considered critical. The EPSS score is below 1 %, indicating a very low but non‑zero likelihood of exploitation at this time, and it is not present in CISA's KEV catalog. The mitigations for this flaw require network‑level protection and patching, as the vulnerability is accessible over TCP and does not require prior authentication.
OpenCVE Enrichment