Executive brief
Oracle Outside In Technology is a suite of software development kits used by developers to extract, normalize, and scrub data from over 600 file formats. A critical vulnerability in the Outside In Filters subcomponent allows an unauthenticated attacker to remotely take control of the software over a network. This could lead to the complete compromise of applications using these tools, potentially resulting in data theft or service disruption.
Technical details
A vulnerability exists in the Outside In Filters subcomponent of Oracle Outside In Technology (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the specific vulnerability class is not detailed in the advisory (categorized as NVD-CWE-noinfo), it allows for a complete compromise of Confidentiality, Integrity, and Availability (CIA triad). The impact is particularly high for software that passes data received over a network directly to the Outside In Technology code. Patches were made available via the Oracle Critical Patch Update (CPU) in January 2017.
Affected products
- Oracle Outside In Technology 8.5.2, 8.5.3
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update