CVE-2011-2264
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.2.0 and 8.3.5.0 allows context-dependent attackers to affect confidentiality, integrity, and availability via unknown vectors related to Outside In…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.2.0 and 8.3.5.0 allows context-dependent attackers to affect confidentiality, integrity, and availability via unknown vectors related to Outside In Filters. NOTE: the previous information was obtained from the July 2011 CPU. Oracle has not commented on claims from a reliable third party that this is a stack-based buffer overflow in the imcdr2.flt library for the CorelDRAW parser.
- CVSS 2.0
- 4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 31.11% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- oracle/fusion middleware
- Source
- secalert_us@oracle.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21660640
- http://www.kb.cert.org/vuls/id/103425US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.htmlPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA11-201A.htmlUS Government Resource
- http://www-01.ibm.com/support/docview.wss?uid=swg21660640
- http://www.kb.cert.org/vuls/id/103425US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.htmlPatch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA11-201A.htmlUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.