Executive brief
Oracle Outside In Technology is a set of software tools used by developers to extract and convert data from hundreds of different file formats. A vulnerability in this component allows a remote attacker to send malicious data that causes the software to crash or freeze. This can lead to a complete denial of service for any business application that relies on these tools to process files.
Technical details
A vulnerability in the Outside In Filters subcomponent of Oracle Outside In Technology (part of Oracle Fusion Middleware) allows for a denial of service. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to cause a frequently repeatable crash or a permanent hang of the Outside In Technology component. This impact is particularly significant for software that passes network-received data directly to the Outside In SDKs. The vulnerability affects versions 8.5.2 and 8.5.3 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Outside In Technology 8.5.2, 8.5.3
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published