Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Application Testing Suite version 13.3.0.1 contains an access‑control weakness that permits an attacker with physical access to the hardware’s communication segment to read and modify data without authentication or a user interface. The flaw leads to confidentiality loss and integrity tampering, allowing unauthorized updates, inserts, or deletes on the application’s data.

Affected Systems

The affected product is Oracle Corporation’s Oracle Application Testing Suite, version 13.3.0.1. No additional vendors or versions are listed in the advisory.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates a high‑severity flaw, with substantial impact on confidentiality and a lesser impact on integrity. The vulnerability requires local physical access (AV:A) and has low attack complexity (AC:L) with no privileges or user interface needed, making it easily exploitable for an attacker who can reach the hardware’s communication segment. The EPSS score is 0.0025 (<1%), and the issue is not listed in the CISA KEV catalog, so the risk assessment relies on the CVSS metrics and the local access requirement.

Generated by OpenCVE AI on August 21, 2026 at 05:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security update for Oracle Application Testing Suite version 13.3.0.1 as published by Oracle.
  • Restrict physical network access to the server hosting the application, allowing only authorized personnel to connect to its physical communication segment.
  • Enforce network segmentation and firewall rules to block traffic from nearby segments to the application’s ports.
  • Enable auditing and monitoring on the application to detect unauthorized read or write operations.

Generated by OpenCVE AI on August 21, 2026 at 05:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Physical Access Exploit Enables Unauthorized Data Access and Modification in Oracle Application Testing Suite 13.3.0.1
Weaknesses CWE-284

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Physical Access Enables Data Manipulation in Oracle Application Testing Suite
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Physical Access Enables Data Manipulation in Oracle Application Testing Suite
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:21:12.656Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70867

cve-icon Vulnrichment

Updated: 2026-08-24T14:07:48.240Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:42.990

Modified: 2026-08-27T18:37:19.243

Link: CVE-2026-70867

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses