PT-2018-2257 · Oracle+1 · Oracle Outside In Technology+1
Published
2018-10-16
·
Updated
2020-08-24
·
CVE-2018-18223
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Outside In Technology (affected versions not specified)
Open Design Alliance Drawings SDK version 2019Update1
Description
The issue is related to insufficient access control in the Outside In Filters (ODA Module) component of Oracle Outside In Technology SDK, which can be exploited by a remote attacker to gain unauthorized access to data or cause a denial of service using the HTTP protocol. Additionally, the Open Design Alliance Drawings SDK has a vulnerability that occurs when reading malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.
Recommendations
For Oracle Outside In Technology, restrict access to the Outside In Filters component to minimize the risk of exploitation.
For Open Design Alliance Drawings SDK version 2019Update1, avoid using the SDK to read malformed files until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Design Alliance Drawings Sdk
Oracle Outside In Technology