Impact
The Oracle Outside In Technology product, part of Oracle Fusion Middleware, contains a flaw in its Outside In PDF Export SDK that allows an unauthenticated attacker who has logged onto the infrastructure hosting the tool to take full control of the component. The bug arises from improper deserialization of data, and an attacker does not need any application‑level credentials. Although taking advantage of the flaw requires a separate user to click or otherwise interact with the target application‘s user interface, the effect of a successful exploitation is complete compromise of confidentiality, integrity, and availability of all data handled by the SDK.
Affected Systems
Only Oracle Outside In Technology version 8.5.8 is known to be affected. No other major releases or separate products from Oracle Fusion Middleware are listed as impacted. The flaw lies within the component named Outside In PDF Export SDK.
Risk and Exploitability
The weakness has a CVSS base score of 7.8, indicating a high‑severity vulnerability. The EPSS score of <1% shows that the likelihood of exploitation in the wild is low, and the flaw is not currently catalogued in CISA’s KEV list. Attackers must have local logon permissions to the host where the application runs and must trigger the exploit through a user‑initiated action in the application; no remote network access is required. Because the flaw permits an attacker to fully takeover the Oracle Outside In Technology component, environments that provide local logon rights to users who can reach the PDF Export SDK face elevated risk and should act quickly.
OpenCVE Enrichment