PT-2018-2258 · Open Design Alliance+1 · Open Design Alliance Drawings Sdk+1

Published

2018-10-16

·

Updated

2020-08-24

·

CVE-2018-18224

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Open Design Alliance Drawings SDK version 2019Update1 Oracle Outside In Technology SDK (affected versions not specified)
Description A vulnerability exists in the file reading procedure, allowing attackers to perform read operations past the end or before the beginning of the intended buffer, potentially obtaining sensitive information from process memory or causing a crash. Additionally, a vulnerability in the Outside In Filters component is related to inadequate access control, which can be exploited by a remote attacker to gain unauthorized access to data or cause a denial of service using the HTTP protocol.
Recommendations For Open Design Alliance Drawings SDK version 2019Update1, consider restricting access to sensitive files and data to minimize the risk of exploitation. For Oracle Outside In Technology SDK, restrict access to the Outside In Filters component to minimize the risk of unauthorized access or denial of service. As a temporary workaround, consider disabling the file reading procedure in Open Design Alliance Drawings SDK until a patch is available. Avoid using the HTTP protocol to access sensitive data in Oracle Outside In Technology SDK until the issue is resolved.

Fix

Improper Access Control

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00358
CVE-2018-18224

Affected Products

Open Design Alliance Drawings Sdk
Oracle Outside In Technology