Executive brief
A vulnerability in the Oracle Application Testing Suite allows an unauthorized person to access sensitive information over the network. This software is used by organizations to automate the testing of web and packaged applications. An exploit could lead to the exposure of critical business data or complete access to all data managed within the testing suite, potentially compromising software development lifecycles and proprietary application details.
Technical details
An information disclosure vulnerability exists in Oracle Application Testing Suite version 13.3.0.1. The flaw is easily exploitable by an unauthenticated attacker with network access via TCP. Successful exploitation allows the attacker to bypass confidentiality controls, resulting in unauthorized access to critical data or complete access to all data accessible by the suite. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact with no impact on integrity or availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Application Testing Suite 13.3.0.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: NVD publication date