Junglewise Threat Intelligence

CVE-2017-3271: Oracle Outside In Technology security bypass in Outside In Filters

CVE-2017-3271 · Severity: high · CVSS 8.6 · Published 2017-01-27

Technologies: Oracle Outside In Technology. Vendors: Oracle.

Executive brief

Oracle Outside In Technology is a suite of software development kits used by applications to extract, normalize, and scrub data from various file formats. A vulnerability in the Outside In Filters component allows an unauthenticated attacker to remotely access or modify sensitive data processed by the software. This could lead to the exposure of confidential information or a partial disruption of services that rely on these filters.

Technical details

A vulnerability exists in the Outside In Filters subcomponent of Oracle Outside In Technology (versions 8.5.2 and 8.5.3). The flaw allows an unauthenticated attacker with network access via HTTP to compromise the component, provided the hosting application passes network-received data directly to the Outside In SDK. Successful exploitation can result in unauthorized read access to all accessible data, unauthorized modification (update, insert, or delete) of some data, and a partial denial of service. The vulnerability is classified as easily exploitable with a low attack complexity. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle Outside In Technology 8.5.2, 8.5.3

Timeline

  • 2017-01-27: advisory: NVD publication date
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats