← Vulnerability feed

Vulnerability record · CVE-2016-0476 · published 21 January 2016

CVE-2016-0476: Oracle enterprise manager grid control vulnerability

Oracle · Enterprise Manager Grid Control

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0477 and CVE-2016-0478. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the reportName parameter.

5.0 CVSS 2.0 Medium EPSS 22% · top 2.4%
5.0CVSS 2.0 base score
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0477 and CVE-2016-0478. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the reportName parameter.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0476 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-1884Jdedwards enterpriseone tools vulnerabilityUnspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impac…EPSS 3.8%9.8CVE-2004-1363Oracle application server vulnerabilityBuffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are e…EPSS 9.1%9.0CVE-2004-1371Oracle application server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedur…EPSS 11%8.5CVE-2004-1364Oracle application server path traversal vulnerabilityDirectory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\b…EPSS 14%7.8CVE-2004-1368Oracle application server vulnerabilityISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the l…EPSS 5.6%7.5CVE-2013-0359Oracle enterprise manager grid control vulnerabilityUnspecified vulnerability in the APM - Application Performance Management component in Oracle Enterprise Manager Grid Control 6.5, 11.1, and 12.1.0.2…EPSS 1.4%7.5CVE-2010-3600Oracle Client System Analyzer remote code execution via exposed JSP uploadAn unspecified vulnerability in the Client System Analyzer component of Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Cont…EPSS 77%analysed7.5CVE-2010-2390Oracle database server vulnerabilityUnspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 1…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2016-0476), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.