Impact
A low‑privileged attacker possessing the Load Testing for Web Apps privilege can exploit a flaw in Oracle Application Testing Suite 13.3.0.1, enabling full compromise of the application. Successful exploitation results in loss of confidentiality, integrity and availability of the suite and effectively allows the attacker to take over the system. The vulnerability is scored 7.8 on the CVSS v3.1 scale, indicating a high level of risk for affected installations.
Affected Systems
Oracle Corporation’s Oracle Application Testing Suite, version 13.3.0.1. No other affected versions are listed.
Risk and Exploitability
The CVSS vector indicates a local attack with low attack complexity, low privileges, no user interaction, and a single scope. Because the EPSS score is reported as <1% and the vulnerability is not listed in CISA KEV, the likelihood of widespread exploitation cannot be determined precisely. The high confidentiality, integrity, and availability impact, combined with the low attack effort, suggests a serious threat. Detection would be limited to the infrastructure where the Suite operates and would require that the attacker already has Load Testing for Web Apps privileges; this conclusion is inferred from the CVSS vector and description.
OpenCVE Enrichment