← Vulnerability feed

Vulnerability record · CVE-2016-0491 · published 21 January 2016

CVE-2016-0491: Oracle Application Testing Suite file upload flaw enables remote code execution

Oracle · Application Testing Suite

Oracle Application Testing Suite (Load Testing for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified flaw affecting integrity and availability. Third-party researchers claim the UploadFileAction servlet lets remote authenticated users upload and execute arbitrary files by placing an asterisk in the fileType parameter, which would yield code execution on the server. Oracle has not confirmed the third-party detail, so the exact mechanism remains partly unverified.

6.4 CVSS 2.0 Medium EPSS 80% · top 0.4%
6.4CVSS 2.0 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that the UploadFileAction servlet allows remote authenticated users to upload and execute arbitrary files via an * (asterisk) character in the fileType parameter.

AV:N/AC:L/Au:N/C:N/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityPublic exploit code and a very high EPSS score make exploitation likely, though the flaw is not in KEV and Oracle has not confirmed the third-party RCE detail.

What it is

Oracle Application Testing Suite (Load Testing for Web Apps) in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 contains an unspecified flaw affecting integrity and availability. Third-party researchers claim the UploadFileAction servlet lets remote authenticated users upload and execute arbitrary files by placing an asterisk in the fileType parameter, which would yield code execution on the server. Oracle has not confirmed the third-party detail, so the exact mechanism remains partly unverified.

Impact

An attacker who can reach the servlet and authenticate can upload and execute arbitrary files, gaining code execution on the Oracle ATS host and compromising the integrity and availability of the application.

Attack surface

Reachable over the network via HTTP against the Oracle ATS Load Testing for Web Apps component; the NVD vector indicates no authentication (Au:N), while the third-party claim requires an authenticated session, so the record is inconsistent on this point. No user interaction is described.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.79948, 99.59th percentile) and multiple references are tagged Exploit, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, indicating public exploit code exists.

What to do

  • Apply the January 2016 Oracle Critical Patch Update for Oracle Application Testing Suite 12.4.0.2 and 12.5.0.2.
  • Restrict network access to the ATS Load Testing servlets, especially UploadFileAction, to trusted management networks.
  • Enforce strong authentication and least privilege on ATS accounts, since the claimed vector requires an authenticated session.
  • If ATS is not required, decommission or isolate the affected instances until patched.
  • Monitor and block uploads of executable file types through the ATS web interface.

Detection

  • Alert on POST requests to UploadFileAction with an asterisk or unusual characters in the fileType parameter.
  • Monitor the ATS web directories for newly written executable files (JSP, WAR, JAR, scripts) and unexpected file creation.
  • Review ATS and web server logs for anomalous upload activity or requests from unfamiliar source addresses.
  • Hunt for child processes spawned by the ATS application server that indicate uploaded code execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0491 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2026-46924Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-35290Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-46876Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2018-1285Apache log4net xml external entity (xxe) vulnerabilityApache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…EPSS 17%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.8CVE-2019-17571Apache Log4j 1.2 SocketServer Deserialization RCELog4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the c…EPSS 69%analysed9.8CVE-2019-2904Oracle application testing suite vulnerabilityVulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 1…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2016-0491), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.