Executive brief
Oracle Application Testing Suite is a software platform used to test web applications. A flaw allows an authenticated user with specific Load Testing privileges to gain complete control over the application through a network connection, potentially exposing sensitive testing data and compromising application availability.
Technical details
This is a privilege escalation vulnerability in Oracle Application Testing Suite 13.3.0.1 accessible via HTTPS. The vulnerability requires an attacker to have low privilege credentials with Load Testing for Web Apps entitlements and network access to the application. The attack has high complexity, indicating multiple preconditions must be met. Successful exploitation results in complete compromise of the Application Testing Suite, affecting confidentiality, integrity, and availability. Patches from Oracle are expected through their Critical Patch Update program.
Affected products
- Oracle Application Testing Suite 13.3.0.1
Timeline
- 2026-08-18: disclosed