Junglewise Threat Intelligence

CVE-2017-3268: Oracle Outside In Technology denial of service in Outside In Filters

CVE-2017-3268 · Severity: high · CVSS 7.5 · Published 2017-01-27

Technologies: Oracle Outside In Technology. Vendors: Oracle.

Executive brief

Oracle Outside In Technology is a set of software tools used by developers to extract and convert data from hundreds of different file formats. A vulnerability in this component allows a remote attacker to send malicious data that causes the software to crash or freeze. This can lead to a complete denial of service for any business application that relies on these tools to process files.

Technical details

A vulnerability in the Outside In Filters subcomponent of Oracle Outside In Technology (part of Oracle Fusion Middleware) allows for a denial of service. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to cause a frequently repeatable crash or a permanent hang of the Outside In Technology component. This impact is particularly significant for software that passes network-received data directly to the Outside In SDKs. The vulnerability affects versions 8.5.2 and 8.5.3 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Outside In Technology 8.5.2, 8.5.3

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats