PatchSiren cyber security CVE debrief
CVE-2017-3267 Oracle CVE debrief
CVE-2017-3267 is a high-severity availability issue in Oracle Outside In Technology (Outside In Filters). According to the advisory and NVD record, an unauthenticated attacker with network access via HTTP can trigger a hang or a frequently repeatable crash, resulting in complete denial of service. The affected supported versions listed in the supplied corpus are 8.5.2 and 8.5.3.
- Vendor
- Oracle
- Product
- CVE-2017-3267
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Organizations that use Oracle Outside In Technology as part of document or file processing workflows, especially where untrusted network data is passed directly into the component.
Technical summary
The supplied NVD data describes a network-reachable, unauthenticated denial-of-service condition in Oracle Outside In Technology with CVSS v3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Impact is limited to availability: successful exploitation can hang the component or cause repeated crashes. NVD lists the vulnerable supported versions as 8.5.2 and 8.5.3.
Defensive priority
High for exposed deployments, because the issue is unauthenticated, network accessible, and can repeatedly disrupt service. Prioritize if the component processes externally supplied content.
Recommended defensive actions
- Identify where Oracle Outside In Technology is deployed and whether versions 8.5.2 or 8.5.3 are in use.
- Review any applications or services that pass network-derived data directly to Outside In Technology.
- Apply Oracle vendor guidance and available updates referenced in the January 2017 CPU advisory.
- If immediate patching is not possible, reduce exposure by limiting network access to the affected service and minimizing untrusted input paths.
- Validate remediation by confirming the vulnerable Outside In Technology versions are no longer present in production paths.
Evidence notes
This debrief is based only on the supplied NVD record and its linked Oracle vendor advisory references. The corpus states the issue is an unauthenticated network DoS against Oracle Outside In Technology, affecting supported versions 8.5.2 and 8.5.3, with CVSS v3.0 7.5 (Availability only). No KEV listing is present in the supplied data.
Official resources
-
CVE-2017-3267 CVE record
CVE.org
-
CVE-2017-3267 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
- Source reference
Published 2017-01-27; the supplied NVD record was last modified on 2026-05-13.