← Vulnerability feed

Vulnerability record · CVE-2016-0487 · published 21 January 2016

CVE-2016-0487: Oracle Application Testing Suite ActionServlet authentication bypass via directory traversal

Oracle · Application Testing Suite

Oracle Application Testing Suite (Test Manager for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified vulnerability that Oracle rates as affecting confidentiality and integrity. Third-party researchers claim it is a directory traversal in the process method of the ActionServlet servlet that lets remote attackers bypass authentication. Oracle has not confirmed the third-party description, so the exact mechanism remains unverified.

6.4 CVSS 2.0 Medium EPSS 51% · top 1.1%
6.4CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0490. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the process method in the ActionServlet servlet, which allows remote attackers to bypass authentication via directory traversal sequences following an unspecified URI string.

AV:N/AC:L/Au:N/C:P/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and has a very high EPSS score, but it is not in KEV and the exact mechanism is disputed, so it warrants prompt patching rather than emergency response.

What it is

Oracle Application Testing Suite (Test Manager for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified vulnerability that Oracle rates as affecting confidentiality and integrity. Third-party researchers claim it is a directory traversal in the process method of the ActionServlet servlet that lets remote attackers bypass authentication. Oracle has not confirmed the third-party description, so the exact mechanism remains unverified.

Impact

An unauthenticated remote attacker can bypass authentication and reach functionality that should require login, gaining partial read and write access to application data. The CVSS 2.0 score of 6.4 reflects partial confidentiality and integrity impact with no availability impact.

Attack surface

Reachable over the network via HTTP against the Oracle Application Testing Suite web interface; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The claimed vector is directory traversal sequences appended to an unspecified URI handled by the ActionServlet process method.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.50888 (98.9th percentile), and references include a Zero Day Initiative advisory, indicating coordinated disclosure of a working exploit path, but no public exploit code is confirmed in this record.

What to do

  • Apply the January 2016 Oracle Critical Patch Update for Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2, which is the vendor patch reference in this record.
  • If patching cannot be done immediately, restrict network access to the Oracle Application Testing Suite web interface to trusted management networks only.
  • Place the application behind a reverse proxy or WAF and block requests containing directory traversal sequences such as ../ and encoded variants.
  • Review and disable any unnecessary Test Manager for Web Apps functionality until the patch is applied.
  • Monitor Oracle security advisories for updated guidance, since Oracle has not commented on the third-party vulnerability description.

Detection

  • Inspect web server and application logs for requests to ActionServlet containing ../, ..%2f, or other traversal encodings.
  • Alert on successful responses to unauthenticated requests that would normally require a session, especially from unexpected source IPs.
  • Correlate HTTP access logs with authentication logs to find requests reaching protected resources without a prior login event.
  • Hunt for anomalous URI patterns or parameter values targeting the Test Manager for Web Apps endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0487 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2026-46924Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-35290Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-46876Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2018-1285Apache log4net xml external entity (xxe) vulnerabilityApache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…EPSS 17%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.8CVE-2019-17571Apache Log4j 1.2 SocketServer Deserialization RCELog4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the c…EPSS 69%analysed9.8CVE-2019-2904Oracle application testing suite vulnerabilityVulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 1…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2016-0487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.