Executive brief
Oracle Application Testing Suite is a software tool used by organizations to automate testing of enterprise applications. An unauthenticated attacker can exploit this vulnerability over the network to gain complete control of the application, potentially leading to unauthorized access to sensitive testing data and infrastructure compromise.
Technical details
This is a difficult-to-exploit remote vulnerability in Oracle Application Testing Suite 13.3.0.1 that allows unauthenticated attackers to achieve remote code execution via HTTP. The vulnerability requires network access but no prior authentication or user interaction. Successful exploitation results in complete compromise of the affected system, with potential impact to confidentiality, integrity, and availability. The CVSS 3.1 score of 8.1 reflects high severity with high impact across all three security dimensions (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected products
- Oracle Application Testing Suite 13.3.0.1
Timeline
- 2026-08-18: disclosed