Impact
A vulnerability in Oracle Application Testing Suite allows an attacker with Test Manager for Web Apps privileges and network access over HTTP to compromise the system. and delete access to data as well as the ability to cause a partial denial of service. The flaw is an improper access control that permits privileged operations beyond the intended scope, leading to confidentiality, integrity, and availability impacts.
Affected Systems
Oracle Application Testing Suite version 13.3.0.1 is affected.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, while the EPSS score is less than 1%, suggesting low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged user capable of sending HTTP requests, making the likely attack vector remote over the network. The risk is heightened by the scope change, as the flaw permits operations on all accessible data within the suite.
OpenCVE Enrichment