Impact
A weakness in Oracle Application Testing Suite version 13.3.0.1 permits an attacker to forge Oracle Net traffic and gain control of the system without authentication. The flaw allows execution of arbitrary code, exposing the entire application and all data it handles. The impact is severe, affecting confidentiality, integrity, and availability with a CVSS v3.1 score of 9.8.
Affected Systems
The vulnerability is limited to Oracle Corporation's Oracle Application Testing Suite, specifically version 13.3.0.1. No other product variants or vendor releases are listed as affected.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation in the wild (<1%), and the flaw is not yet listed in the CISA KEV catalog. Nevertheless, the high CVSS score and the fact that an unauthenticated attacker can trigger the exploit over the network make it a high‑priority target for adversaries, especially in environments where the application is exposed externally or to untrusted sources.
OpenCVE Enrichment