Impact
A vulnerability in Oracle Application Testing Suite version 13.3.0.1 allows a low‑privileged user who holds the Load Testing for Web Apps role to compromise the system via HTTPS. Successful exploitation grants the attacker control over the entire application testing environment, resulting in loss of confidentiality, integrity, and availability. The CVSS 3.1 base score of 7.5 reflects a high severity risk with all three impact dimensions affected.
Affected Systems
Affected systems include Oracle Corporation’s Oracle Application Testing Suite 13.3.0.1. No other versions are listed as impacted in the current advisories.
Risk and Exploitability
The CVSS base score indicates high severity, and the EPSS score of < 1 % suggests a very low likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a low‑privileged Load Testing user and occurs over HTTPS, enabling remote control of the application testing suite.
OpenCVE Enrichment