Vulnerability record · CVE-2016-0488 · published 21 January 2016
CVE-2016-0488: Oracle Application Testing Suite Load Testing for Web Apps flaw allows remote confidentiality and integrity impact
Oracle · Application Testing Suite
Oracle Application Testing Suite (Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2) contains an unspecified vulnerability in the Load Testing for Web Apps component. Oracle's advisory describes only confidentiality and integrity impact via unknown vectors, while third-party researchers claim it is a directory traversal in the isAllowedUrl function of the admin pages that bypasses authentication. The discrepancy matters because the vendor has not confirmed the traversal or authentication bypass claim.
Description
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0492. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function in the admin pages, which allows remote attackers to bypass authentication and gain administrator access via directory traversal sequences following a URI entry that does not require authentication.
AV:N/AC:L/Au:N/C:P/I:P/A:N
Automated analysis
high priorityHigh EPSS and a claimed authentication bypass with administrator access raise risk, though Oracle has not confirmed the traversal details and the CVSS base score is only 6.4.
What it is
Oracle Application Testing Suite (Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2) contains an unspecified vulnerability in the Load Testing for Web Apps component. Oracle's advisory describes only confidentiality and integrity impact via unknown vectors, while third-party researchers claim it is a directory traversal in the isAllowedUrl function of the admin pages that bypasses authentication. The discrepancy matters because the vendor has not confirmed the traversal or authentication bypass claim.
Impact
An unauthenticated remote attacker can affect confidentiality and integrity of the affected component. If the third-party directory traversal claim is accurate, the attacker could bypass authentication and gain administrator access.
Attack surface
Reachable over the network with no authentication required per the CVSS vector (AV:N/AC:L/Au:N). The third-party claim involves a URI entry that does not require authentication, but Oracle has not confirmed this path.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is high (0.6531, 99.22nd percentile), and references include third-party advisories (ZDI-16-035, SecurityFocus, SecurityTracker) alongside the Oracle patch advisory.
What to do
- Apply the Oracle January 2016 Critical Patch Update for Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2.
- Restrict network access to the Application Testing Suite admin and Load Testing interfaces to trusted management networks.
- If patching is delayed, disable or block the Load Testing for Web Apps component until the update is applied.
- Review web server and application logs for directory traversal sequences in requests to admin pages.
Detection
- Monitor HTTP requests to Application Testing Suite admin endpoints for traversal sequences such as ../ or encoded variants.
- Alert on unauthenticated access attempts to admin pages that normally require authentication.
- Correlate Application Testing Suite logs with unexpected administrator session creation or configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/81104 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1034734 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-16-035 | Third Party AdvisoryVDB Entry |
| http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/81104 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1034734 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-16-035 | Third Party AdvisoryVDB Entry |
Track CVE-2016-0488 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0488), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.