Unspecified Vulnerability in Oracle Application Testing Suite in Oracle Enterprise Manager
CVE-2016-0485
Summary
An unspecified vulnerability exists within the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control versions 12.4.0.2 and 12.5.0.2. This vulnerability allows remote attackers to potentially breach confidentiality through unknown vectors involving the Test Manager for Web Apps. There are claims this issue might relate to directory traversal vulnerabilities present in the DownloadServlet servlet, enabling remote attackers to read arbitrary files by manipulating the reportName parameter. Oracle has not yet confirmed or dismissed these allegations, which distinguishes this vulnerability from others noted in the same security bulletin.
References
EPSS Score
8% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved