6.3

CVE-2020-1945

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheAnt Version >= 1.1 <= 1.9.14
ApacheAnt Version >= 1.10.0 <= 1.10.7
CanonicalUbuntu Linux Version19.10
FedoraprojectFedora Version31
FedoraprojectFedora Version32
OpensuseLeap Version15.2
OracleBanking Enterprise Collections Version >= 2.7.0 <= 2.9.0
OracleBanking Liquidity Management Version >= 14.0.0 <= 14.4.0
OracleBanking Platform Version >= 2.4.0 <= 2.9.0
OracleCommunications Asap Version7.3
OracleCommunications Diameter Signaling Router Version >= 8.0.0 <= 8.2.2
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleEnterprise Repository Version11.1.1.7.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleHealth Sciences Information Manager Version >= 3.0 <= 3.0.2
OraclePrimavera Gateway Version >= 16.2.0 <= 16.2.11
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.7
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleReal-time Decision Server Version3.2.1.0
OracleRetail Back Office Version14.0
OracleRetail Back Office Version14.1
OracleRetail Bulk Data Integration Version16.0.3.0
OracleRetail Central Office Version14.0
OracleRetail Central Office Version14.1
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.4.0
OracleRetail Financial Integration Version16.0.3.0
OracleRetail Integration Bus Version14.1
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0
OracleRetail Integration Bus Version15.0.4.0
OracleRetail Integration Bus Version16.0
OracleRetail Integration Bus Version16.0.3.0
OracleRetail Integration Bus Version19.0.1.0
OracleRetail Item Planning Version15.0.3
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.4.0
OracleRetail Service Backbone Version16.0.3.0
OracleRetail Service Backbone Version19.0.1.0
OracleTimesten In-memory Database Version < 11.2.2.8.27
OracleTimesten In-memory Database Version11.2.2.8.49
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version2.2.0.0.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.03
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.3 1 5.2
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 3.3 3.4 4.9
AV:L/AC:M/Au:N/C:P/I:P/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://usn.ubuntu.com/4380-1/
Vendor Advisory
Mailing List