Oracle Outside In Technology CVE-2012-3107 Remote Code Execution Vulnerability
BID:54504
Info
Oracle Outside In Technology CVE-2012-3107 Remote Code Execution Vulnerability
| Bugtraq ID: | 54504 |
| Class: | Unknown |
| CVE: |
CVE-2012-3107 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2012 12:00AM |
| Updated: | Mar 19 2015 08:12AM |
| Credit: | Oracle |
| Vulnerable: |
Symantec Enterprise Vault 10.0 Oracle Oracle Outside In Technology 8.3.7 Oracle Oracle Outside In Technology 8.3.5 Microsoft Office SharePoint Server 2010 SP1 Microsoft FAST Search Server 2010 for SharePoint Service Pack 1 0 Microsoft FAST Search Server 2010 for SharePoint 0 Microsoft Exchange Server 2010 SP2 Microsoft Exchange Server 2010 SP1 Microsoft Exchange Server 2007 SP3 Microsoft Exchange Server 2007 SP2 Microsoft Exchange Server 2007 SP 1 Microsoft Exchange Server 2007 SP3 McAfee Security for Microsoft Sharepoint 2.5 McAfee Security for Microsoft Exchange 7.6 McAfee Security for Lotus Domino 7.5 McAfee Host Data Loss Prevention 9.0 Patch 2 McAfee Host Data Loss Prevention 9.0 McAfee GroupShield for Exchange 2010 7.0.2 McAfee GroupShield for Exchange 2003/2007 7.0.1 McAfee Email Gateway 7.0 Patch 1 McAfee Email Gateway 7.0 McAfee Email and Web Security Appliance 5.6 Patch 4 McAfee Email and Web Security Appliance 5.6 Patch 3 McAfee Email and Web Security Appliance 5.5 Patch 6 McAfee Email and Web Security Appliance 5.1 Patch 4 McAfee Email and Web Security Appliance 5.1 Guidance Software Encase Forensics 7.04 Guidance Software Encase Forensics 6.19.3 Acdsystems Canvas 14 AccessData Group FTK 4.0 AccessData Group FTK 3.4 AccessData Group FTK 3.3 AccessData Group FTK 3.2 |
| Not Vulnerable: |
Symantec Enterprise Vault 10.0.2 Microsoft Office SharePoint Server 2007 SP3 (64-bit) Microsoft Office SharePoint Server 2007 SP2 (64-bit) Microsoft Exchange Server 2003 SP2 Microsoft Exchange Server 2000 SP3 |
Discussion
Oracle Outside In Technology CVE-2012-3107 Remote Code Execution Vulnerability
Oracle Outside In Technology is prone to a remote code-execution vulnerability.
The 'Outside In Filters' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
This vulnerability affects the following supported versions:
8.3.5, 8.3.7
Oracle Outside In Technology is prone to a remote code-execution vulnerability.
The 'Outside In Filters' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
This vulnerability affects the following supported versions:
8.3.5, 8.3.7
Exploit / POC
Oracle Outside In Technology CVE-2012-3107 Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Outside In Technology CVE-2012-3107 Remote Code Execution Vulnerability
References:
References:
- Oracle Homepage (Oracle)
- Oracle Outside In vulnerabilities with McAfee Security for Microsoft Exchange 7. (McAfee)
- Security for Microsoft SharePoint 2.5.1 Hotfix 788524 Release Notes (McAfee)
- AccessData Information for VU#118913 (AccessData Group)
- ACD Systems International Information for VU#118913 (ACD Systems International)
- Guidance Software, Inc. Information for VU#118913 (Guidance Software)
- McAfee Security Bulletin - Updates fix Oracle 'Outside In' vulnerabilities for m (McAfee)
- Microsoft Security Bulletin MS12-058 (Microsoft)
- Microsoft Security Bulletin MS12-067 - Important (Microsoft)
- Oracle Critical Patch Update Advisory - July 2012 (Oracle)
- Oracle Outside In contains multiple exploitable vulnerabilities (US-CERT)
- Security Advisories Relating to Symantec Products - Symantec Enterprise Vault Up (Symantec)
- Vulnerabilities in Microsoft Exchange and FAST Search Server 2010 for SharePoint (Microsoft)