Impact
The defect is an access‑control flaw that can be triggered by sending a crafted HTTP request to Oracle Application Testing Suite 13.3.0.1 while logged in with the Load Testing for Web Apps role. The flaw allows a low‑privileged user to read critical data and, with additional human cooperation from a distinct user, to gain read access to all data in the suite and to perform unauthorized updates, inserts or deletes on data owned by other users, resulting in confidential data exposure and integrity violations.
Affected Systems
Only Oracle Application Testing Suite 13.3.0.1 is directly affected. The description indicates a scope change, meaning that successful exploitation could also threaten other Oracle products that interact with the suite.
Risk and Exploitability
The CVSS v3.1 base score of 7.6 classifies the issue as high severity, with confidentiality impact rated high and integrity low. The EPSS score of less than 1% suggests exploitation is unlikely but not impossible. The vulnerability is not yet listed in CISA's KEV catalog. Attackers need network reach to the HTTP endpoint and a low‑privilege Load Testing for Web Apps account; they also require a user other than themselves to provide assistance, which lowers the likelihood of a fully remote attack but remains a concern for environments where internal users grant such privileges.
OpenCVE Enrichment