Executive brief
Oracle Outside In Technology is a suite of software development kits used by various applications to extract, normalize, and scrub data from hundreds of different file formats. A vulnerability in the 'Outside In Filters' component allows an unauthenticated attacker to remotely crash the service or cause it to hang. This results in a complete denial-of-service, preventing the host application from processing files and potentially disrupting business operations that rely on automated data ingestion.
Technical details
A vulnerability in the Outside In Filters subcomponent of Oracle Outside In Technology (part of Oracle Fusion Middleware) allows for remote denial-of-service. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the specific root cause (e.g., buffer overflow or null pointer dereference) is not detailed in the advisory, the impact is a complete loss of availability (hang or repeatable crash). The vulnerability's severity assumes the host application passes network-received data directly to the Outside In SDK without prior sanitization. Patches were made available via the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Outside In Technology 8.5.2, 8.5.3
Timeline
- 2017-01-27: advisory: Initial release of CVE-2017-3267 by Oracle
- 2017-01-27: patched: Fix released in January 2017 Critical Patch Update