Unspecified Vulnerability in Oracle Enterprise Manager Grid Control Affecting Test Manager for Web Apps
CVE-2016-0486
Currently unrated
Summary
An unspecified vulnerability within the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control could allow remote attackers to compromise the confidentiality of the system. This issue has been linked to Test Manager for Web Apps and is distinct from other identified vulnerabilities. While Oracle has not explicitly confirmed claims suggesting that this entails a directory traversal flaw in the DownloadServlet servlet, it is suspected that attackers might exploit this to access arbitrary files by manipulating the exportFileName parameter.
References
EPSS Score
8% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved