Vulnerability record · CVE-2016-0489 · published 21 January 2016
CVE-2016-0489: Oracle Application Testing Suite Test Manager directory traversal file upload
Oracle · Application Testing Suite
Oracle Application Testing Suite (Test Manager for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified vulnerability that Oracle patched in its January 2016 CPU. Third-party researchers claim it is a directory traversal in the ActionServlet servlet, where the tempfilename parameter in a ReportImage action lets an authenticated user write and execute arbitrary files. Oracle has not confirmed that technical detail, so the exact mechanism remains partly unverified.
Description
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the ActionServlet servlet, which allows remote authenticated users to upload and execute arbitrary files via directory traversal sequences in the tempfilename parameter in a ReportImage action.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows authenticated remote file upload and possible code execution, and EPSS is very high despite no KEV listing.
What it is
Oracle Application Testing Suite (Test Manager for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified vulnerability that Oracle patched in its January 2016 CPU. Third-party researchers claim it is a directory traversal in the ActionServlet servlet, where the tempfilename parameter in a ReportImage action lets an authenticated user write and execute arbitrary files. Oracle has not confirmed that technical detail, so the exact mechanism remains partly unverified.
Impact
An attacker with valid credentials can read, modify, or disrupt data and potentially execute arbitrary code on the server, affecting confidentiality, integrity, and availability.
Attack surface
Reachable over the network via the Test Manager for Web Apps servlet interface; the CVSS vector (AV:N/AC:L/Au:S) indicates authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high at roughly 0.55 (99th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Apply the Oracle January 2016 Critical Patch Update for Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2.
- Restrict network access to the Application Testing Suite / Test Manager web interface to trusted management networks.
- Limit and audit accounts with access to Test Manager for Web Apps; remove unused or default accounts.
- If the patch cannot be applied, disable or block the ActionServlet ReportImage action and validate the tempfilename parameter against traversal sequences.
- Monitor the Test Manager upload/temp directories for unexpected file creation or execution.
Detection
- Inspect web server and application logs for ReportImage actions with tempfilename values containing ../ or encoded traversal sequences.
- Alert on file writes to web-accessible or temp directories originating from the Test Manager process.
- Monitor for new or modified executable files in Application Testing Suite directories.
- Correlate authenticated Test Manager sessions with unusual outbound or process-spawning activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/81184 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1034734 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-16-038 | Third Party AdvisoryVDB Entry |
| http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/81184 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1034734 | Third Party AdvisoryVDB Entry |
| http://www.zerodayinitiative.com/advisories/ZDI-16-038 | Third Party AdvisoryVDB Entry |
Track CVE-2016-0489 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0489), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.