Improper input validation in Oracle Outside In Technology - CVE-2023-22127

 

Improper input validation in Oracle Outside In Technology - CVE-2023-22127

Published: October 18, 2023


Vulnerability identifier: #VU82224
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22127
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to read and manipulate data.

The vulnerability exists due to improper input validation within the Content Access SDK, Image Export SDK, PDF Export SDK, HTML Export SDK component in Oracle Outside In Technology. A remote authenticated user can exploit this vulnerability to read and manipulate data.


Affected software

Oracle Outside In Technology
IBM Engineering Requirements Management DOORS Next

How to mitigate CVE-2023-22127

Install updates from vendor's website.

IBM Engineering Requirements Management DOORS Next - addressed in versions 7.0.2 ifix 30, 7.0.3 ifix 7

External References

Related Security Bulletins