Impact
Oracle Application Testing Suite version 13.3.0.1 contains an access‑control weakness that permits an attacker with physical access to the hardware’s communication segment to read and modify data without authentication or a user interface. The flaw leads to confidentiality loss and integrity tampering, allowing unauthorized updates, inserts, or deletes on the application’s data.
Affected Systems
The affected product is Oracle Corporation’s Oracle Application Testing Suite, version 13.3.0.1. No additional vendors or versions are listed in the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a high‑severity flaw, with substantial impact on confidentiality and a lesser impact on integrity. The vulnerability requires local physical access (AV:A) and has low attack complexity (AC:L) with no privileges or user interface needed, making it easily exploitable for an attacker who can reach the hardware’s communication segment. The EPSS score is 0.0025 (<1%), and the issue is not listed in the CISA KEV catalog, so the risk assessment relies on the CVSS metrics and the local access requirement.
OpenCVE Enrichment