Impact
The flaw in Oracle Application Testing Suite 13.3.0.1 enables a user who holds the Test Manager for Web Apps privilege to leverage low‑privilege access through the HTTP interface and trigger a full takeover of the appliance. This can result in the attacker gaining unauthorized data access, modifying or deleting test data, and controlling the entire application testing environment, thereby compromising confidentiality, integrity, and availability. The vulnerability stems from weaknesses that allow user role escalation and inadequate authority validation.
Affected Systems
Oracle Application Testing Suite version 13.3.0.1 from Oracle Corporation.
Risk and Exploitability
With a CVSS base score of 8.8 the issue is classified as high severity. The EPSS score of less than 1% indicates that current exploitation attempts are rare, and the vulnerability is not listed in CISA's KEV catalog. An attacker would need network access to the appliance’s HTTP port and a legitimate Test Manager for Web Apps account; no additional privileges are required beyond the role granted to that account.
OpenCVE Enrichment