PT-2009-3593 · Oracle+1 · Oracle Application Server+2

Published

2009-04-15

·

Updated

2014-01-14

·

CVE-2009-1011

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Application Server versions 8.2.2 through 8.3.0
Description The issue affects confidentiality, integrity, and availability, and is related to HTML. It is reportedly due to multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
Recommendations For Oracle Application Server versions 8.2.2 through 8.3.0, consider restricting access to the Outside In Technology component until a fix is available. As a temporary workaround, avoid using the affected function that parses Microsoft Office files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-1011

Affected Products

Office
Oracle Application Server
Outside In Technology