Multiple Remote Code Execution Vulnerabilities in Oracle Outside In Technology
Article Content
Oracle Outside In Technology has been found to have multiple vulnerabilities that allow remote attackers to execute arbitrary code. These vulnerabilities affect installations of the software and require user interaction, such as visiting a malicious page or opening a malicious file. The flaws include issues in parsing PostScript, GEM, WPS, and PDF files, leading to heap-based buffer overflows and integer overflows. Oracle has issued updates to address these vulnerabilities. The vulnerabilities are identified as ZDI-26-635, ZDI-26-636, ZDI-26-637, and ZDI-26-638. The vulnerabilities were reported to the vendor on 2026-04-08, and the advisories were publicly released on 2026-09-09. Security professionals are advised to apply the updates promptly to mitigate risks.
Key Points: • Four critical vulnerabilities in Oracle Outside In Technology allow remote code execution. • User interaction is required to exploit these vulnerabilities via malicious files or pages. • Oracle has released updates to address these vulnerabilities as of September 9, 2026.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.