cbcvebase.

Oracle Application Testing Suite vulnerabilities

75 known vulnerabilities affecting oracle/application_testing_suite.

Total CVEs
75
CISA KEV
1
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL11HIGH31MEDIUM33

Vulnerabilities

Page 1 of 4
CVE-2020-11023P1MEDIUMCVSS 6.1KEVPoCv13.3.0.12020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2020-11022P1MEDIUMCVSS 6.1ExploitedPoCv13.3.0.12020-04-29
CVE-2020-11022 [MEDIUM] CWE-79 CVE-2020-11022: In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sa In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCv12.5.0.3v13.1.0.1+4 more2019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2017-5645P1CRITICALCVSS 9.8PoCv13.3.0.12017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2016-0492P2MEDIUMCVSS 6.4PoCv12.4.0.2v12.5.0.22016-01-21
CVE-2016-0492 [MEDIUM] CVE-2016-0492: Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Man Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 20
nvd
CVE-2019-0227P2HIGHCVSS 7.5PoCv13.2.0.1v13.3.0.12019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2016-0491P2MEDIUMCVSS 6.4PoCv12.4.0.2v12.5.0.22016-01-21
CVE-2016-0491 [MEDIUM] CVE-2016-0491: Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Man Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party c
nvd
CVE-2018-1270P2CRITICALCVSS 9.8v12.5.0.3v13.1.0.1+2 more2018-04-06
CVE-2018-1270 [CRITICAL] CWE-94 CVE-2018-1270: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution
nvd
CVE-2019-17571P2CRITICALCVSS 9.8v13.3.0.12019-12-20
CVE-2019-17571 [CRITICAL] CWE-502 CVE-2019-17571: Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted dat Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
nvd
CVE-2018-1275P2CRITICALCVSS 9.8v12.5.0.3v13.1.0.1+2 more2018-04-11
CVE-2018-1275 [CRITICAL] CVE-2018-1275: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
nvd
CVE-2018-1271P3MEDIUMCVSS 5.9PoCv12.5.0.3v13.1.0.1+2 more2018-04-06
CVE-2018-1271 [MEDIUM] CWE-22 CVE-2018-1271: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a reque
nvd
CVE-2020-5398P2HIGHCVSS 7.5v13.3.0.12020-01-17
CVE-2020-5398 [HIGH] CWE-79 CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0 In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
nvd
CVE-2019-2904P2CRITICALCVSS 9.8v12.5.0.3v13.1.0.1+2 more2019-10-16
CVE-2019-2904 [CRITICAL] CVE-2019-2904: Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF F Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerabil
nvd
CVE-2016-0488P2MEDIUMCVSS 6.4v12.4.0.2v12.5.0.22016-01-21
CVE-2016-0488 [MEDIUM] CVE-2016-0488: Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Man Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0492. NOTE: the previous information is from the January 20
nvd
CVE-2018-1285P2CRITICALCVSS 9.8v13.3.0.12020-05-11
CVE-2018-1285 [CRITICAL] CWE-611 CVE-2018-1285: Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net conf Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
nvd
CVE-2019-2557P3MEDIUMCVSS 6.3PoCv13.3.0.12019-04-23
CVE-2019-2557 [MEDIUM] CVE-2019-2557: Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Product Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponent: Load Testing for Web Apps). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attack
nvd
CVE-2016-0487P3MEDIUMCVSS 6.4v12.4.0.2v12.5.0.22016-01-21
CVE-2016-0487 [MEDIUM] CVE-2016-0487: Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Man Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0490. NOTE: the previous information is from the January 20
nvd
CVE-2026-35290P2CRITICALCVSS 9.8v13.3.0.12026-07-21
CVE-2026-35290 [CRITICAL] CWE-284 CVE-2026-35290: Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3. Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3
nvd
CVE-2026-46876P2CRITICALCVSS 9.8v13.3.0.12026-07-21
CVE-2026-46876 [CRITICAL] CWE-284 CVE-2026-46876: Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3. Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite.
nvd
CVE-2026-46924P2CRITICALCVSS 9.8v13.3.0.12026-07-21
CVE-2026-46924 [CRITICAL] CWE-284 CVE-2026-46924: Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3. Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3
nvd