Impact
A flaw in the access control logic of Oracle Application Testing Suite 13.3.0.1 enables any network user to execute arbitrary code, which is classified as CWE-284. This weakness allows an attacker who can reach the service over TCP to fully compromise the instance, leading to loss of confidentiality, integrity, and availability for all data handled by the suite.
Affected Systems
Oracle Corporation’s Oracle Application Testing Suite version 13.3.0.1 is the only product listed as affected. No other vendors or product variants appear in the CNA data.
Risk and Exploitability
The CVSS v3.1 score of 9.8 indicates critical severity, and the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not yet catalogued in CISA KEV. Based on the CVE description, the attack vector is inbound TCP to the service, requires no authentication, and can be executed from any remote host that can reach the vulnerable port.
OpenCVE Enrichment