HTTP: Oracle Outside In Excel GelFrame Out-of-bounds Read

This signature detects attempt to exploit an out-of-bounds read vulnerability which exists in Oracle Outside-In, a set of libraries used to decode many file formats. This vulnerability can be exploited by causing an application that uses the vulnerable library to handle a malformed Excel document. Depending on the application, user interaction may be required. Successful exploitation could result in information disclosure which could be used to further compromise the target system.

Extended Description

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L).

Affected Products

Oracle outside_in_technology

Short Name
HTTP:EXCEL-GELFRM-OOB
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-2992 CVE-2018-3147 Excel GelFrame In Oracle Out-of-bounds Outside Read bid:104762
Release Date
10/01/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3728
False Positive
Unknown
Vendors

Oracle

CVSS Score

5.8

4.3

Found a potential security threat?