PatchSiren cyber security CVE debrief
CVE-2017-3267 Oracle CVE debrief
CVE-2017-3267 is a high-severity availability issue in Oracle Outside In Technology (Outside In Filters). According to the advisory and NVD record, an unauthenticated attacker with network access via HTTP can trigger a hang or a frequently repeatable crash, resulting in complete denial of service. The affected supported versions listed in the supplied corpus are 8.5.2 and 8.5.3.
- Vendor
- Oracle
- Product
- Outside In Technology
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Organizations that use Oracle Outside In Technology as part of document or file processing workflows, especially where untrusted network data is passed directly into the component.
Technical summary
The supplied NVD data describes a network-reachable, unauthenticated denial-of-service condition in Oracle Outside In Technology with CVSS v3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Impact is limited to availability: successful exploitation can hang the component or cause repeated crashes. NVD lists the vulnerable supported versions as 8.5.2 and 8.5.3.
Defensive priority
High for exposed deployments, because the issue is unauthenticated, network accessible, and can repeatedly disrupt service. Prioritize if the component processes externally supplied content.
Recommended defensive actions
- Identify where Oracle Outside In Technology is deployed and whether versions 8.5.2 or 8.5.3 are in use.
- Review any applications or services that pass network-derived data directly to Outside In Technology.
- Apply Oracle vendor guidance and available updates referenced in the January 2017 CPU advisory.
- If immediate patching is not possible, reduce exposure by limiting network access to the affected service and minimizing untrusted input paths.
- Validate remediation by confirming the vulnerable Outside In Technology versions are no longer present in production paths.
Evidence notes
This debrief is based only on the supplied NVD record and its linked Oracle vendor advisory references. The corpus states the issue is an unauthenticated network DoS against Oracle Outside In Technology, affecting supported versions 8.5.2 and 8.5.3, with CVSS v3.0 7.5 (Availability only). No KEV listing is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3267 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3267
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3267 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3267
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.