SB2019021302 - Microsoft update for Oracle Outside In Library component for Microsoft Exchange Server



SB2019021302 - Microsoft update for Oracle Outside In Library component for Microsoft Exchange Server

Published: February 13, 2019

Security Bulletin ID SB2019021302
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 21
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 21 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2018-18224)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters ODA Module component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


2) Input validation error (CVE-ID: CVE-2018-18223)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters ODA Module component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


3) Input validation error (CVE-ID: CVE-2018-3234)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


4) Input validation error (CVE-ID: CVE-2018-3233)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


5) Input validation error (CVE-ID: CVE-2018-3232)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


6) Input validation error (CVE-ID: CVE-2018-3231)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


7) Input validation error (CVE-ID: CVE-2018-3230)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


8) Input validation error (CVE-ID: CVE-2018-3229)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


9) Input validation error (CVE-ID: CVE-2018-3228)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


10) Input validation error (CVE-ID: CVE-2018-3227)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


11) Input validation error (CVE-ID: CVE-2018-3226)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


12) Input validation error (CVE-ID: CVE-2018-3225)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


13) Input validation error (CVE-ID: CVE-2018-3224)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


14) Input validation error (CVE-ID: CVE-2018-3223)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


15) Input validation error (CVE-ID: CVE-2018-3222)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


16) Input validation error (CVE-ID: CVE-2018-3302)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


17) Input validation error (CVE-ID: CVE-2018-3221)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


18) Input validation error (CVE-ID: CVE-2018-3220)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or delete data.


19) Input validation error (CVE-ID: CVE-2018-3219)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or delete data.


20) Input validation error (CVE-ID: CVE-2018-3218)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or manipulate data.


21) Input validation error (CVE-ID: CVE-2018-3217)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or manipulate data.


Remediation

Install update from vendor's website.