Remote File Upload Vulnerability in Oracle Enterprise Manager
CVE-2016-0490
Currently unrated
What is CVE-2016-0490?
An unspecified vulnerability exists in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control. This flaw may allow remote attackers to compromise the integrity and confidentiality of the system through unknown vectors related to Test Manager for Web Apps. There are suggestions that this may be a directory traversal vulnerability in the UploadServlet, potentially enabling attackers to upload and execute arbitrary files by manipulating the filename header.