Junglewise Threat Intelligence

CVE-2017-3269: Oracle Outside In Technology denial of service in Outside In Filters

CVE-2017-3269 · Severity: high · CVSS 7.5 · Published 2017-01-27

Technologies: Oracle Outside In Technology. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Outside In Technology, a suite of software development kits used by various applications to extract and normalize data from different file formats. An unauthenticated attacker can exploit this flaw over a network to cause the software to hang or crash repeatedly. This results in a complete denial of service, preventing the affected applications from processing files or performing their intended functions.

Technical details

A vulnerability in the Outside In Filters subcomponent of Oracle Outside In Technology (part of Oracle Fusion Middleware) allows for unauthenticated denial of service. The flaw is easily exploitable via the HTTP protocol, assuming the host application passes network-received data directly to the Outside In SDK. Successful exploitation allows an attacker to cause a frequently repeatable crash or a complete hang of the component. The vulnerability affects versions 8.5.2 and 8.5.3. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle Outside In Technology 8.5.2, 8.5.3

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle and NVD publication
  • 2017-01-27: patched: Fixed in Oracle January 2017 Critical Patch Update

References

Related threats