Remote Code Execution Vulnerability in Oracle Application Testing Suite
CVE-2016-0484

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2016

Summary

An unspecified vulnerability in the Oracle Application Testing Suite, part of Oracle Enterprise Manager Grid Control, poses a risk to data confidentiality. Remote attackers might exploit this vulnerability through undisclosed methods related to Test Manager for Web Apps. Notably, there are claims suggesting this may involve directory traversal in the DownloadServlet servlet, potentially allowing unauthorized access to sensitive files through manipulation of the scriptPath parameter.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.