CVE-2016-0492
CVE-2016-0492 is a medium-severity vulnerability in Oracle Application Testing Suite with a CVSS 2.0 base score of 6.4. Its EPSS exploit-prediction score of 92% places it in the 100th percentile, indicating an elevated likelihood of exploitation.
Key facts
- Severity: Medium (CVSS 2.0 base score 6.4)
- EPSS exploit prediction: 92% (100th percentile)
- Actively exploited: Not listed in CISA KEV
- Affected product: Oracle Application Testing Suite
- Published:
- Last modified:
Description
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do.
Frequently asked questions
- What is CVE-2016-0492?
- Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do.
- How severe is CVE-2016-0492?
- CVE-2016-0492 has a CVSS 2.0 base score of 6.4, rated medium severity.
- Is CVE-2016-0492 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 92% (100th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2016-0492?
- CVE-2016-0492 primarily affects Oracle Application Testing Suite. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2016-0492?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2016-0492 published?
- CVE-2016-0492 was published on 2016-01-21 and last updated on 2026-06-17.
References
- http://packetstormsecurity.com/files/137175/Oracle-ATS-Arbitrary-File-Upload.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.rapid7.com/db/modules/exploit/multi/http/oracle_ats_file_upload
- http://www.securityfocus.com/bid/81158
- http://www.securitytracker.com/id/1034734
- http://www.zerodayinitiative.com/advisories/ZDI-16-042
- https://www.exploit-db.com/exploits/39691/
- https://www.exploit-db.com/exploits/39852/
Affected products (2)
- cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*
More vulnerabilities in Oracle Application Testing Suite
- CVE-2026-46924 — Critical (CVSS 9.8): Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily…
- CVE-2026-46876 — Critical (CVSS 9.8): Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily…
- CVE-2026-35290 — Critical (CVSS 9.8): Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily…
- CVE-2018-1285 — Critical (CVSS 9.8): Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files.…
- CVE-2020-10683 — Critical (CVSS 9.8): dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE…
- CVE-2019-17571 — Critical (CVSS 9.8): Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be…