Executive brief
Oracle Outside In Technology is a set of software development kits (SDKs) used by applications to extract, normalize, and scrub content from over 600 file formats. A vulnerability in the 'Outside In Filters' component allows an unauthenticated attacker to remotely access or modify sensitive data processed by the software. This could lead to the exposure of critical information or a partial disruption of services for applications relying on these filters.
Technical details
This vulnerability exists within the Outside In Filters subcomponent of Oracle Outside In Technology (versions 8.5.2 and 8.5.3). It is classified as easily exploitable, allowing an unauthenticated attacker with network access via HTTP to compromise the library. The root cause is related to how the filters process data, potentially leading to unauthorized access to all data accessible by the SDK, as well as unauthorized update, insert, or delete capabilities. While the CVSS score is 8.6, the actual impact depends on how the integrating software implements the SDK and whether it passes network-received data directly to the Outside In code. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Outside In Technology 8.5.2, 8.5.3
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published