Improper input validation in Oracle Outside In Technology - CVE-2023-22127

 

Improper input validation in Oracle Outside In Technology - CVE-2023-22127

Published: October 18, 2023


Vulnerability identifier: #VU82224
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-22127
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Oracle Outside In Technology
Software vendor:
Oracle

Description

The vulnerability allows a remote authenticated user to read and manipulate data.

The vulnerability exists due to improper input validation within the Content Access SDK, Image Export SDK, PDF Export SDK, HTML Export SDK component in Oracle Outside In Technology. A remote authenticated user can exploit this vulnerability to read and manipulate data.


Remediation

Install updates from vendor's website.

External links