Junglewise Threat Intelligence

CVE-2017-3311: Oracle Application Testing Suite unauthorized data manipulation in Test Manager for Web Apps

CVE-2017-3311 · Severity: medium · CVSS 5.3 · Published 2017-01-27

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's Application Testing Suite, a tool used by organizations to automate the testing of web applications. An unauthenticated attacker could remotely modify, insert, or delete certain data within the system. This could compromise the integrity of testing results or application configurations without requiring any user interaction.

Technical details

A vulnerability in the Test Manager for Web Apps subcomponent of Oracle Application Testing Suite (part of Enterprise Manager Grid Control) allows for unauthorized data manipulation. The flaw is exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation grants the attacker the ability to perform unauthorized updates, insertions, or deletions of data accessible to the Application Testing Suite. The vulnerability affects versions 12.4.0.2, 12.5.0.2, and 12.5.0.3. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle Application Testing Suite 12.4.0.2, 12.5.0.2, 12.5.0.3

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle January 2017 Critical Patch Update published

References

Related threats