← Vulnerability feed

Vulnerability record · CVE-2016-0488 · published 21 January 2016

CVE-2016-0488: Oracle Application Testing Suite Load Testing for Web Apps flaw allows remote confidentiality and integrity impact

Oracle · Application Testing Suite

Oracle Application Testing Suite (Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2) contains an unspecified vulnerability in the Load Testing for Web Apps component. Oracle's advisory describes only confidentiality and integrity impact via unknown vectors, while third-party researchers claim it is a directory traversal in the isAllowedUrl function of the admin pages that bypasses authentication. The discrepancy matters because the vendor has not confirmed the traversal or authentication bypass claim.

6.4 CVSS 2.0 Medium EPSS 65% · top 0.8%
6.4CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0492. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function in the admin pages, which allows remote attackers to bypass authentication and gain administrator access via directory traversal sequences following a URI entry that does not require authentication.

AV:N/AC:L/Au:N/C:P/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityHigh EPSS and a claimed authentication bypass with administrator access raise risk, though Oracle has not confirmed the traversal details and the CVSS base score is only 6.4.

What it is

Oracle Application Testing Suite (Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2) contains an unspecified vulnerability in the Load Testing for Web Apps component. Oracle's advisory describes only confidentiality and integrity impact via unknown vectors, while third-party researchers claim it is a directory traversal in the isAllowedUrl function of the admin pages that bypasses authentication. The discrepancy matters because the vendor has not confirmed the traversal or authentication bypass claim.

Impact

An unauthenticated remote attacker can affect confidentiality and integrity of the affected component. If the third-party directory traversal claim is accurate, the attacker could bypass authentication and gain administrator access.

Attack surface

Reachable over the network with no authentication required per the CVSS vector (AV:N/AC:L/Au:N). The third-party claim involves a URI entry that does not require authentication, but Oracle has not confirmed this path.

Exploitation

Not listed in CISA KEV and no ransomware usage documented. EPSS is high (0.6531, 99.22nd percentile), and references include third-party advisories (ZDI-16-035, SecurityFocus, SecurityTracker) alongside the Oracle patch advisory.

What to do

  • Apply the Oracle January 2016 Critical Patch Update for Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2.
  • Restrict network access to the Application Testing Suite admin and Load Testing interfaces to trusted management networks.
  • If patching is delayed, disable or block the Load Testing for Web Apps component until the update is applied.
  • Review web server and application logs for directory traversal sequences in requests to admin pages.

Detection

  • Monitor HTTP requests to Application Testing Suite admin endpoints for traversal sequences such as ../ or encoded variants.
  • Alert on unauthenticated access attempts to admin pages that normally require authentication.
  • Correlate Application Testing Suite logs with unexpected administrator session creation or configuration changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0488 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2026-46924Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-35290Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-46876Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2018-1285Apache log4net xml external entity (xxe) vulnerabilityApache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…EPSS 17%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.8CVE-2019-17571Apache Log4j 1.2 SocketServer Deserialization RCELog4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the c…EPSS 69%analysed9.8CVE-2019-2904Oracle application testing suite vulnerabilityVulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 1…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2016-0488), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.