Impact
The vulnerability in Oracle Outside In Technology’s Outside In Core component allows an unauthenticated attacker who has logged onto the infrastructure where the software runs to compromise the application. It requires human interaction from a person other than the attacker, but the attacker need only local access and no privileges. Successful exploitation can lead to complete takeover, resulting in confidentiality, integrity, and availability loss. The CVSS 3.1 base score is 7.8, reflecting high impact with the vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Systems
The affected product is Oracle Outside In Technology (Outside In Core) version 8.5.8, which is part of Oracle Fusion Middleware. No other versions or products are listed as affected.
Risk and Exploitability
The high confidentiality, integrity, and availability impacts, coupled with a local attack vector requiring minimal effort, make this a pressing risk for any environment running Oracle Outside In Technology 8.5.8. The lack of a publicly disclosed patch or work‑around in the input emphasizes the need for immediate remediation.
OpenCVE Enrichment