Impact
A local vulnerability in Oracle Outside In Technology allows an attacker who is not authenticated but has access to the same infrastructure to compromise the application. The attacker needs to rely on a secondary user to provide the necessary human interaction to trigger the exploit. Once successful, the attacker can take full control of the service, exposing all data and disrupting business operations by compromising confidentiality, integrity, and availability.
Affected Systems
Oracle Outside In Technology 8.5.8 - part of Oracle Fusion Middleware, component Outside In Core - is affected. All installations running the specified version are vulnerable; no other versions are listed.
Risk and Exploitability
The CVSS 7.8 score marks this as a high-severity flaw. EPSS is <1%, indicating a very low but nonzero likelihood of exploitation. The issue is not listed in CISA KEV. The vulnerability requires an attacker who is not authenticated but has local logon to the same infrastructure and relies on a human user to trigger the exploit. While it does not enable remote exploitation without local access, the presence of users with local privileges can still pose significant risk. Mitigation measures—such as isolating the machine that runs Outside In Technology, enforcing strict local access controls, and monitoring logs—can reduce the risk, but a vendor patch is recommended to close the vulnerability.
OpenCVE Enrichment