Unspecified Vulnerability in Oracle Application Testing Suite in Oracle Enterprise Manager
CVE-2016-0485

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2016

Summary

An unspecified vulnerability exists within the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control versions 12.4.0.2 and 12.5.0.2. This vulnerability allows remote attackers to potentially breach confidentiality through unknown vectors involving the Test Manager for Web Apps. There are claims this issue might relate to directory traversal vulnerabilities present in the DownloadServlet servlet, enabling remote attackers to read arbitrary files by manipulating the reportName parameter. Oracle has not yet confirmed or dismissed these allegations, which distinguishes this vulnerability from others noted in the same security bulletin.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.