Impact
The vulnerability is an unauthenticated HTTP access flaw that allows an attacker with network connectivity to create, delete, or modify critical data in Oracle Application Testing Suite. This flaw undermines confidentiality and integrity by granting the attacker full control over any data managed by the suite, including test configurations and results. The weakness is rooted in improper authorization (CWE-284).
Affected Systems
Oracle Corporation’s Application Testing Suite version 13.3.0.1 is affected. The flaw targets the HTTP interface of this product.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 classifies the flaw as critical, while an EPSS score of <1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is network reachable over HTTP, requires no credentials, and can be triggered easily, making it a potent threat to confidentiality and integrity. It is not listed in the CISA KEV catalog, but its impact and ease of exploitation warrant prompt action.
OpenCVE Enrichment