Oracle Outside In Technology CVE-2012-3110 Remote Code Execution Vulnerability
BID:54506
Info
Oracle Outside In Technology CVE-2012-3110 Remote Code Execution Vulnerability
| Bugtraq ID: | 54506 |
| Class: | Unknown |
| CVE: |
CVE-2012-3110 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2012 12:00AM |
| Updated: | Oct 09 2012 06:30PM |
| Credit: | Oracle |
| Vulnerable: |
Symantec Enterprise Vault 10.0 Microsoft Office SharePoint Server 2010 SP1 Microsoft Exchange Server 2007 SP3 Microsoft Exchange Server 2007 SP2 Microsoft Exchange Server 2007 SP 1 Microsoft Exchange Server 2007 SP3 McAfee Host Data Loss Prevention 9.0 McAfee Email Gateway 7.0 Patch 1 McAfee Email Gateway 7.0 McAfee Email and Web Security Appliance 5.6 Patch 3 McAfee Email and Web Security Appliance 5.5 Patch 6 McAfee Email and Web Security Appliance 5.1 Patch 4 McAfee Email and Web Security Appliance 5.1 AccessData Group FTK 3.4 AccessData Group FTK 3.3 AccessData Group FTK 3.2 |
| Not Vulnerable: |
Microsoft Exchange Server 2003 SP2 Microsoft Exchange Server 2000 SP3 |
Discussion
Oracle Outside In Technology CVE-2012-3110 Remote Code Execution Vulnerability
Oracle Outside In Technology is prone to a remote code-execution vulnerability.
The 'Outside In Filters' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
This vulnerability affects the following supported versions:
8.3.5, 8.3.7
Oracle Outside In Technology is prone to a remote code-execution vulnerability.
The 'Outside In Filters' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
This vulnerability affects the following supported versions:
8.3.5, 8.3.7
Exploit / POC
Oracle Outside In Technology CVE-2012-3110 Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Outside In Technology CVE-2012-3110 Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Outside In Technology CVE-2012-3110 Remote Code Execution Vulnerability
References:
References:
- Oracle Homepage (Oracle)
- Oracle Outside In vulnerabilities with McAfee Security for Microsoft Exchange 7. (McAfee)
- Security for Microsoft SharePoint 2.5.1 Hotfix 788524 Release Notes (McAfee)
- AccessData Information for VU#118913 (AccessData Group)
- ACD Systems International Information for VU#118913 (ACD Systems International)
- Guidance Software, Inc. Information for VU#118913 (Guidance Software)
- McAfee Security Bulletin - Updates fix Oracle 'Outside In' vulnerabilities for m (McAfee)
- Microsoft Security Bulletin MS12-058 (Microsoft)
- Microsoft Security Bulletin MS12-067 - Important (Microsoft)
- Oracle Critical Patch Update Advisory - July 2012 (Oracle)
- Oracle Outside In contains multiple exploitable vulnerabilities (US-CERT)
- Security Advisories Relating to Symantec Products - Symantec Enterprise Vault Up (Symantec)
- Vulnerabilities in Microsoft Exchange and FAST Search Server 2010 for SharePoint (Microsoft)