PT-2018-2257 · Oracle+1 · Oracle Outside In Technology+1

Published

2018-10-16

·

Updated

2020-08-24

·

CVE-2018-18223

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Oracle Outside In Technology (affected versions not specified) Open Design Alliance Drawings SDK version 2019Update1
Description The issue is related to insufficient access control in the Outside In Filters (ODA Module) component of Oracle Outside In Technology SDK, which can be exploited by a remote attacker to gain unauthorized access to data or cause a denial of service using the HTTP protocol. Additionally, the Open Design Alliance Drawings SDK has a vulnerability that occurs when reading malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.
Recommendations For Oracle Outside In Technology, restrict access to the Outside In Filters component to minimize the risk of exploitation. For Open Design Alliance Drawings SDK version 2019Update1, avoid using the SDK to read malformed files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00357
CVE-2018-18223

Affected Products

Open Design Alliance Drawings Sdk
Oracle Outside In Technology