PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3267 Oracle CVE debrief

CVE-2017-3267 is a high-severity availability issue in Oracle Outside In Technology (Outside In Filters). According to the advisory and NVD record, an unauthenticated attacker with network access via HTTP can trigger a hang or a frequently repeatable crash, resulting in complete denial of service. The affected supported versions listed in the supplied corpus are 8.5.2 and 8.5.3.

Vendor
Oracle
Product
CVE-2017-3267
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Organizations that use Oracle Outside In Technology as part of document or file processing workflows, especially where untrusted network data is passed directly into the component.

Technical summary

The supplied NVD data describes a network-reachable, unauthenticated denial-of-service condition in Oracle Outside In Technology with CVSS v3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Impact is limited to availability: successful exploitation can hang the component or cause repeated crashes. NVD lists the vulnerable supported versions as 8.5.2 and 8.5.3.

Defensive priority

High for exposed deployments, because the issue is unauthenticated, network accessible, and can repeatedly disrupt service. Prioritize if the component processes externally supplied content.

Recommended defensive actions

  • Identify where Oracle Outside In Technology is deployed and whether versions 8.5.2 or 8.5.3 are in use.
  • Review any applications or services that pass network-derived data directly to Outside In Technology.
  • Apply Oracle vendor guidance and available updates referenced in the January 2017 CPU advisory.
  • If immediate patching is not possible, reduce exposure by limiting network access to the affected service and minimizing untrusted input paths.
  • Validate remediation by confirming the vulnerable Outside In Technology versions are no longer present in production paths.

Evidence notes

This debrief is based only on the supplied NVD record and its linked Oracle vendor advisory references. The corpus states the issue is an unauthenticated network DoS against Oracle Outside In Technology, affecting supported versions 8.5.2 and 8.5.3, with CVSS v3.0 7.5 (Availability only). No KEV listing is present in the supplied data.

Official resources

Published 2017-01-27; the supplied NVD record was last modified on 2026-05-13.