5.5
CVE-2020-17521
- EPSS 1.05%
- Veröffentlicht 07.12.2020 20:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
- Erkennungen
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Snapcenter Version -
Oracle ≫ Agile Engineering Data Management Version 6.2.1.0
Oracle ≫ Agile Plm Mcad Connector Version 3.4
Oracle ≫ Agile Plm Mcad Connector Version 3.6
Oracle ≫ Agile Product Lifecycle Management Version 9.3.3
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Process Management Suite Version 12.2.1.4.0
Oracle ≫ Communications Brm - Elastic Charging Engine Version 11.3.0.9.0
Oracle ≫ Communications Brm - Elastic Charging Engine Version 12.0.0.3
Oracle ≫ Communications Diameter Signaling Router Version 8.4.0.0
Oracle ≫ Communications Services Gatekeeper Version 6.0
Oracle ≫ Communications Services Gatekeeper Version 6.1
Oracle ≫ Communications Services Gatekeeper Version 7.0
Oracle ≫ Healthcare Data Repository Version 7.0.2
Oracle ≫ Hospitality Opera 5 Version 5.6
Oracle ≫ Insurance Policy Administration Version >= 11.0 <= 11.3.1
Oracle ≫ Jd Edwards Enterpriseone Orchestrator Version 9.2.6.0
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.10
Oracle ≫ Primavera Unifier Version >= 17.7 <= 17.12
Oracle ≫ Primavera Unifier Version 16.1
Oracle ≫ Primavera Unifier Version 16.2
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Primavera Unifier Version 19.12
Oracle ≫ Primavera Unifier Version 20.12
Oracle ≫ Retail Bulk Data Integration Version 15.0.3.0
Oracle ≫ Retail Bulk Data Integration Version 16.0.3.0
Oracle ≫ Retail Merchandising System Version 16.0.3
Oracle ≫ Retail Store Inventory Management Version 14.1.3.10
Oracle ≫ Retail Store Inventory Management Version 15.0.3.5
Oracle ≫ Retail Store Inventory Management Version 16.0.3.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.05% | 0.598 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuapr2021.html
https://security.netapp.com/advisory/ntap-20201218-0006/
https://groovy-lang.org/security.html#CVE-2020-17521
https://lists.apache.org/thread.html/r4b2f13c302eec98838ff7475253091fb9b75bc1038016ba00ebf6c08%40%3Cdev.atlas.apache.org%3E
https://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3E
https://lists.apache.org/thread.html/rea63a4666ba245d2892471307772a2d8ce0f0741f341d6576625c1b3%40%3Cdev.atlas.apache.org%3E