CVE-2016-0491 is an unspecified vulnerability in Oracle Application Testing Suite (ATS) versions 12.4.0.2 and 12.5.0.2, specifically impacting the Load Testing for Web Apps component. While Oracle's official description is vague, third-party claims suggest it involves an arbitrary file upload vulnerability in the UploadFileAction servlet, allowing remote authenticated users to execute arbitrary files. This vulnerability has a CVSS score of 6.4, indicating a medium severity. It is network-exploitable with low attack complexity, potentially leading to integrity and availability impacts. The EPSS score of 0.88432 suggests a high likelihood of exploitation. Exploit intelligence confirms the existence of Metasploit modules and ExploitDB entries for this vulnerability, including an arbitrary file upload and an authentication bypass. Despite the availability of exploit code, there is no evidence of active exploitation (not in KEV) and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.4.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:* | ||
12.5.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.