← Vulnerability feed

Vulnerability record · CVE-2016-0489 · published 21 January 2016

CVE-2016-0489: Oracle Application Testing Suite Test Manager directory traversal file upload

Oracle · Application Testing Suite

Oracle Application Testing Suite (Test Manager for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified vulnerability that Oracle patched in its January 2016 CPU. Third-party researchers claim it is a directory traversal in the ActionServlet servlet, where the tempfilename parameter in a ReportImage action lets an authenticated user write and execute arbitrary files. Oracle has not confirmed that technical detail, so the exact mechanism remains partly unverified.

6.5 CVSS 2.0 Medium EPSS 55% · top 1.0%
6.5CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the ActionServlet servlet, which allows remote authenticated users to upload and execute arbitrary files via directory traversal sequences in the tempfilename parameter in a ReportImage action.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows authenticated remote file upload and possible code execution, and EPSS is very high despite no KEV listing.

What it is

Oracle Application Testing Suite (Test Manager for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified vulnerability that Oracle patched in its January 2016 CPU. Third-party researchers claim it is a directory traversal in the ActionServlet servlet, where the tempfilename parameter in a ReportImage action lets an authenticated user write and execute arbitrary files. Oracle has not confirmed that technical detail, so the exact mechanism remains partly unverified.

Impact

An attacker with valid credentials can read, modify, or disrupt data and potentially execute arbitrary code on the server, affecting confidentiality, integrity, and availability.

Attack surface

Reachable over the network via the Test Manager for Web Apps servlet interface; the CVSS vector (AV:N/AC:L/Au:S) indicates authentication is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high at roughly 0.55 (99th percentile), suggesting elevated likelihood of attempted exploitation.

What to do

  • Apply the Oracle January 2016 Critical Patch Update for Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2.
  • Restrict network access to the Application Testing Suite / Test Manager web interface to trusted management networks.
  • Limit and audit accounts with access to Test Manager for Web Apps; remove unused or default accounts.
  • If the patch cannot be applied, disable or block the ActionServlet ReportImage action and validate the tempfilename parameter against traversal sequences.
  • Monitor the Test Manager upload/temp directories for unexpected file creation or execution.

Detection

  • Inspect web server and application logs for ReportImage actions with tempfilename values containing ../ or encoded traversal sequences.
  • Alert on file writes to web-accessible or temp directories originating from the Test Manager process.
  • Monitor for new or modified executable files in Application Testing Suite directories.
  • Correlate authenticated Test Manager sessions with unusual outbound or process-spawning activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2026-46924Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-35290Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-46876Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2018-1285Apache log4net xml external entity (xxe) vulnerabilityApache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…EPSS 17%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.8CVE-2019-17571Apache Log4j 1.2 SocketServer Deserialization RCELog4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the c…EPSS 69%analysed9.8CVE-2019-2904Oracle application testing suite vulnerabilityVulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 1…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2016-0489), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.