Impact
This vulnerability arises from an improper access control flaw that allows an attacker who has logon access to the infrastructure where Oracle Application Testing Suite runs to compromise the application. The flaw, identified as CWE‑269, enables takeover of the suite, resulting in loss of confidentiality, integrity and availability of all data processed by it. The likely attack vector is an unauthenticated attacker who can log into the host, but successful exploitation also requires human interaction from a party other than the attacker.
Affected Systems
Oracle application testing suite version 13.3.0.1 is the only product mentioned as affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.0 indicates a moderate to high severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires attackers to first obtain local logon access to the infrastructure and then rely on a human facilitator; therefore the risk is lower in environments with strict internal controls. Nonetheless, once achieved, the attacker can gain full control of the suite and compromise all data it handles.
OpenCVE Enrichment