CVE-2016-0492 is an unspecified vulnerability in Oracle Application Testing Suite (ATS) versions 12.4.0.2 and 12.5.0.2, potentially allowing remote attackers to affect confidentiality and integrity. While Oracle's description is vague, third-party claims suggest it's a directory traversal vulnerability enabling authentication bypass and arbitrary file upload. With a CVSS score of 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N), it poses a moderate risk, allowing unauthenticated remote attackers to compromise data. This vulnerability has publicly available exploit code, including a Metasploit module, and a high EPSS score (0.91458), indicating a significant likelihood of exploitation despite no recorded active exploitation or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.4.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:* | ||
12.5.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.