CVE-2016-0492
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 92.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 92.14% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application testing suite
- Source
- secalert_us@oracle.com
References
- http://packetstormsecurity.com/files/137175/Oracle-ATS-Arbitrary-File-Upload.htmlExploit, Third Party Advisory, VDB Entry
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlVendor Advisory
- http://www.rapid7.com/db/modules/exploit/multi/http/oracle_ats_file_uploadThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/81158Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034734Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-042Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39691/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39852/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/137175/Oracle-ATS-Arbitrary-File-Upload.htmlExploit, Third Party Advisory, VDB Entry
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlVendor Advisory
- http://www.rapid7.com/db/modules/exploit/multi/http/oracle_ats_file_uploadThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/81158Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034734Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-042Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39691/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39852/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.