Sceawere

Vulnerability Detail

CVE-2026-70867UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Application Testing Suite Access Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Application Testing Suite
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data.
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:17:42.990Z",
  "pubdate": "2026-08-18T21:17:42.990Z",
  "executiveSummary": "An easily exploitable vulnerability affects Oracle Application Testing Suite version 13.3.0.1, potentially allowing an unauthenticated adversary to compromise the system.\nThe vulnerability requires the attacker to have access to the physical communication segment attached to the hardware where Oracle Application Testing Suite executes.\nSuccessful exploitation results in severe confidentiality and integrity impacts, granting unauthorized access to critical data or complete access to all accessible data within the application.\nAdditionally, attackers can achieve unauthorized update, insert, or delete access to a subset of accessible data.\nThe severity of this flaw is reflected by a CVSS 3.1 Base Score of 7.1 with the vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N.\nThe risk implications include data compromise and unauthorized modification, necessitating immediate administrative attention to secure the physical communication segment and apply vendor-supplied patches.",
  "technicalDetails": "The vulnerability resides within Oracle Application Testing Suite version 13.3.0.1, specifically impacting how data access controls and communication interfaces are managed at the physical network segment level.\nThe root cause stems from insufficient validation or authentication mechanisms protecting internal communication channels exposed to the local physical communication segment.\nBecause the attack vector is categorized as Adjacent (AV:A), the adversary must be positioned on the same physical or logical local network segment (such as the same local area network or shared physical switch) as the hardware hosting the vulnerable Oracle Application Testing Suite instance.\nThe attack complexity is low (AC:L), meaning the exploitation does not require specialized conditions, and the attacker can consistently trigger the flaw without advanced race conditions or complex bypassing techniques.\nNo privileges (PR:N) and no user interaction (UI:N) are required, allowing any unauthenticated entity positioned on the adjacent network segment to initiate malicious interactions directly against the target system.\nThe attack flow proceeds as follows: First, the unauthenticated attacker establishes a presence on the physical communication segment attached to the target hardware. Second, the attacker crafts and transmits specialized network traffic or payloads directly targeting the vulnerable interface or component within Oracle Application Testing Suite. Third, due to the lack of adequate authentication and access restrictions on this interface, the application processes the unpatched communication channel requests. Finally, the attacker achieves unauthorized access to critical data or complete access to all accessible data repositories, alongside the capability to execute unauthorized insert, update, or delete operations on specific data subsets.\nThe Scope is Unchanged (S:U), indicating that the security scope remains within the authorization boundary of the affected application, yet the impact on Confidentiality is High (C:H) and Integrity is Low (I:L), while Availability is unaffected (A:N)."
}
CVE-2026-70867: Oracle Application Testing Suite Access Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere