Vulnerability record · CVE-2015-6013 · published 22 January 2016
CVE-2015-6013: Oracle outside in technology vulnerability
Oracle · Outside In Technology
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4808, CVE-2015-6014, CVE-2015-6015, and CVE-2016-0432. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is a stack-based buffer overflow in Oracle Outside In 8.5.2 and earlier, which allows remote attackers to execute arbitrary code via a crafted WK4 file.
Description
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4808, CVE-2015-6014, CVE-2015-6015, and CVE-2016-0432. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is a stack-based buffer overflow in Oracle Outside In 8.5.2 and earlier, which allows remote attackers to execute arbitrary code via a crafted WK4 file.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | Vendor Advisory |
| http://www.securityfocus.com/bid/81227 | |
| http://www.securitytracker.com/id/1034711 | |
| https://www.kb.cert.org/vuls/id/916896 | Third Party AdvisoryUS Government Resource |
| http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | Vendor Advisory |
| http://www.securityfocus.com/bid/81227 | |
| http://www.securitytracker.com/id/1034711 | |
| https://www.kb.cert.org/vuls/id/916896 | Third Party AdvisoryUS Government Resource |
Track CVE-2015-6013 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-6013), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.