Unspecified Vulnerability in Oracle Enterprise Manager Grid Control Affecting Test Manager for Web Apps
CVE-2016-0486

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2016

Summary

An unspecified vulnerability within the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control could allow remote attackers to compromise the confidentiality of the system. This issue has been linked to Test Manager for Web Apps and is distinct from other identified vulnerabilities. While Oracle has not explicitly confirmed claims suggesting that this entails a directory traversal flaw in the DownloadServlet servlet, it is suspected that attackers might exploit this to access arbitrary files by manipulating the exportFileName parameter.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.