CVE-2016-0491: Medium severity oracle application testing suite vulnerability
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that the UploadFileAction servlet allows remote authenticated users to upload and execute arbitrary files via an (asterisk) character in the fileType parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0491?
CVE-2016-0491 is rated as critical due to its potential impact on the integrity and availability of affected systems.
How do I fix CVE-2016-0491?
To fix CVE-2016-0491, it is recommended to apply the latest security patches provided by Oracle for the affected versions of the Application Testing Suite.
What versions are affected by CVE-2016-0491?
CVE-2016-0491 affects Oracle Application Testing Suite versions 12.4.0.2 and 12.5.0.2.
Can CVE-2016-0491 be exploited remotely?
Yes, CVE-2016-0491 can be exploited by remote attackers, allowing them to affect the system's integrity and availability.
Is there a known workaround for CVE-2016-0491?
There are no specific workarounds for CVE-2016-0491, and applying security patches is the recommended mitigation strategy.