CVE-2018-3225 describes a vulnerability in Oracle Outside In Technology, specifically affecting versions 8.5.3 and 8.5.4 of its Filters subcomponent. This easily exploitable flaw allows an unauthenticated attacker with network access via HTTP to compromise the software. Successful attacks, which require user interaction, can lead to a complete denial of service (frequently repeatable crashes) and unauthorized read access to a subset of accessible data. The vulnerability has a CVSS 3.0 Base Score of 7.1 (High), indicating significant confidentiality and availability impacts. The attack vector is network-based with low attack complexity, but user interaction is required. While the CVSS score assumes network data input, it may be lower if data is not received over a network. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community attention, with no social media discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.5.3CPE matchmatch criteria | cpe:2.3:a:oracle:outside_in_technology:8.5.3:*:*:*:*:*:*:* | ||
8.5.4CPE matchmatch criteria | cpe:2.3:a:oracle:outside_in_technology:8.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.