Vulnerability record · CVE-2016-0492 · published 21 January 2016
CVE-2016-0492: Oracle Application Testing Suite authentication bypass and file upload flaw
Oracle · Application Testing Suite
Oracle Application Testing Suite in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 has an unspecified vulnerability in Load Testing for Web Apps affecting confidentiality and integrity. Oracle has not confirmed third-party claims that it is a directory traversal in the isAllowedUrl function allowing authentication bypass and arbitrary file upload.
Description
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do.
AV:N/AC:L/Au:N/C:P/I:P/A:N
Automated analysis
high priorityUnauthenticated remote exploitation is demonstrated by public exploit code and a very high EPSS score, though the CVSS base score is only 6.4 and KEV listing is absent.
What it is
Oracle Application Testing Suite in Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 has an unspecified vulnerability in Load Testing for Web Apps affecting confidentiality and integrity. Oracle has not confirmed third-party claims that it is a directory traversal in the isAllowedUrl function allowing authentication bypass and arbitrary file upload.
Impact
An unauthenticated remote attacker can bypass authentication and upload arbitrary files, compromising confidentiality and integrity of the affected system.
Attack surface
Reachable over the network via HTTP with no authentication required, per the CVSS vector AV:N/AC:L/Au:N and the described traversal through olt/Login.do to olt/UploadFileUpload.do.
Exploitation
Not listed in CISA KEV, but EPSS is 0.92145 (99.8th percentile) and multiple references are tagged Exploit, including Exploit-DB and Rapid7 Metasploit module entries.
What to do
- Apply the Oracle January 2016 Critical Patch Update for Application Testing Suite 12.4.0.2 and 12.5.0.2.
- Restrict network access to the Application Testing Suite web interface to trusted hosts only.
- If patching is not possible, disable or block the Load Testing for Web Apps component until the update is applied.
- Monitor for and block directory traversal sequences in requests to olt endpoints at the reverse proxy or WAF.
Detection
- Alert on HTTP requests containing traversal sequences such as ../ or ..%2f targeting olt/Login.do or olt/UploadFileUpload.do.
- Monitor for file creation or modification in Application Testing Suite web directories outside normal deployment activity.
- Review web server logs for unauthenticated POST requests to UploadFileUpload.do or similar upload endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0492 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0492), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.