Input validation error in Oracle Outside In Technology - CVE-2018-3227

 

Input validation error in Oracle Outside In Technology - CVE-2018-3227

Published: February 12, 2019


Vulnerability identifier: #VU17601
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3227
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to bypass certain security restrictions.

The vulnerability exists due to unspecified error within the Outside In Filters component. A remote attacker can trick the victim into sending a specially crafted request to the affected application and gain access to potentially sensitive information or trigger denial of service conditions.


Affected software

Oracle Outside In Technology
Microsoft Exchange Server

How to mitigate CVE-2018-3227

Install updates from vendor's website.

Microsoft Exchange Server - addressed in versions 2010 Service Pack 3 Update Rollup 26, 2013 Cumulative Update 22 15.00.1473.003, 2016 Cumulative Update 12 15.01.1713.005, 2019 Cumulative Update 1 15.02.0330.005

External References

Related Security Bulletins