Impact
Oracle Application Testing Suite 13.3.0.1 contains a vulnerability that permits an unauthenticated attacker with network access to compromise the application. The flaw allows the attacker to take full control of the system, leading to loss of confidentiality, integrity, and availability. The vulnerability is exploitable over HTTP without requiring authentication or user interaction.
Affected Systems
The affected product is Oracle Corporation’s Oracle Application Testing Suite version 13.3.0.1. No other vendors or product versions are listed by the CNA for this entry.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity. The EPSS score is < 1%, indicating a low probability of exploitation, but the lack of authentication requirements and an airborne attack vector over HTTP still make exploitation a realistic threat to any externally reachable instance. The vulnerability is not currently listed in the CISA KEV catalog, but its potential for full takeover warrants urgent attention. Attackers would send specially crafted HTTP requests to the exposed service, leveraging the flaw to execute arbitrary code.
OpenCVE Enrichment