The security vulnerability exists in the Oracle Outside In Libraries when parsing specially crafted files. An attacker could exploit this by uploading a malicious file to a site using FAST Search to index, which could result in arbitrary code execution.
Note:
- FAST Search Server for SharePoint is only affected by this issue when Advanced Filter Pack is enabled. By default, Advanced Filter Pack is disabled.
- Microsoft licenses Oracle Outside In Libraries from Oracle.
The information provided herein is on "as is" basis, without warranty of any kind.