Impact
An attacker who has received the Load Testing for Web Apps role can exploit a flaw in Oracle Application Testing Suite 13.3.0.1. The vulnerability allows the low‑privileged attacker to carry out privileged actions over HTTPS, leading to full control over the suite, with confidentiality, integrity and availability all compromised. The CVSS v3.1 base score of 8.8 reflects the high impact of this privilege escalation.
Affected Systems
Oracle Application Testing Suite version 13.3.0.1 from Oracle Corporation.
Risk and Exploitability
The high CVSS score indicates that the flaw poses a serious risk to the affected system. The EPSS score of less than 1 % suggests that current exploitation activity is very low, and the vulnerability is not listed in CISA KEV, implying no publicly available exploit yet. Attackers that can access the load‑testing role and reach the HTTPS endpoint can leverage the flaw to elevate privileges and take over the application without needing additional authentication.
OpenCVE Enrichment