Remote Authentication Bypass in Oracle Application Testing Suite
CVE-2016-0492
Currently unrated
What is CVE-2016-0492?
An unspecified vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control versions 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity. The vulnerability pertains to Load Testing for Web Applications and may involve a directory traversal issue in the isAllowedUrl function, enabling remote attackers to bypass authentication by employing directory traversal sequences after a non-authenticated URI entry. This has been illustrated through exploited vectors such as olt/Login.do/../../olt/UploadFileUpload.do.