Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker with network access to use TCP to take control of Oracle Application Testing Suite. It is described as easily exploitable and results in a total takeover, impacting the confidentiality, integrity, and availability of the system. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and a base score of 9.8 reflect the severe nature of the flaw.

Affected Systems

Oracle Corporation’s Oracle Application Testing Suite version 13.3.0.1 is affected. No other versions or products were listed.

Risk and Exploitability

With a CVSS score of 9.8 the flaw is considered critical. The EPSS score is below 1 %, indicating a very low but non‑zero likelihood of exploitation at this time, and it is not present in CISA's KEV catalog. The mitigations for this flaw require network‑level protection and patching, as the vulnerability is accessible over TCP and does not require prior authentication.

Generated by OpenCVE AI on August 3, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s patch for Oracle Application Testing Suite 13.3.0.1 released in the CPU July 2026 advisory
  • Block or restrict external TCP connectivity to the OATS service unless explicitly authorized
  • Verify that the firewall and network segmentation policies isolate the OATS installation from untrusted networks

Generated by OpenCVE AI on August 3, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit Compromises Oracle Application Testing Suite

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit Compromises Oracle Application Testing Suite

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:19:37.663Z

Reserved: 2026-04-01T20:03:40.836Z

Link: CVE-2026-35290

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:57.221Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:30:16Z

Weaknesses