5.8

CVE-2021-29425

Exploit

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheCommons Io Version2.2 Update-
ApacheCommons Io Version2.3 Update-
ApacheCommons Io Version2.4 Update-
ApacheCommons Io Version2.5 Update-
ApacheCommons Io Version2.6 Update-
DebianDebian Linux Version9.0
OracleAccess Manager Version11.1.2.3.0
OracleAccess Manager Version12.2.1.3.0
OracleAccess Manager Version12.2.1.4.0
OracleAgile Plm Version9.3.6
OracleApplication Testing Suite Version13.3.0.1
OracleBanking Apis Version18.1
OracleBanking Apis Version18.2
OracleBanking Apis Version18.3
OracleBanking Apis Version19.1
OracleBanking Apis Version19.2
OracleBanking Apis Version20.1
OracleBanking Apis Version21.1
OracleBanking Enterprise Default Managment Version >= 2.3.0 <= 2.4.0
OracleBanking Party Management Version2.7.0
OracleBanking Platform Version >= 2.3.0 <= 2.4.1
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleBlockchain Platform Version < 21.1.2
OracleCommerce Guided Search Version11.3.2
OracleCommunications Contacts Server Version8.0.0.6.0
OracleCommunications Convergence Version3.0.2.2.0
OracleCommunications Design Studio Version >= 7.4.0 <= 7.4.2
OracleCommunications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
OracleCommunications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
OracleFlexcube Core Banking Version >= 11.6.0 <= 11.8.0
OracleFlexcube Core Banking Version5.2.0
OracleFlexcube Core Banking Version11.10.0
OracleFusion Middleware Mapviewer Version12.2.1.4.0
OracleHealth Sciences Information Manager Version >= 3.0.1 <= 3.0.4
OracleHelidon Version1.4.7
OracleHelidon Version2.2.0
OracleInsurance Rules Palette Version11.0.2
OracleInsurance Rules Palette Version11.1.0
OracleInsurance Rules Palette Version11.2.8
OracleInsurance Rules Palette Version11.3.0
OracleInsurance Rules Palette Version11.3.1
OracleOss Support Tools Version < 2.12.42
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleReal User Experience Insight Version13.4.1.0
OracleReal User Experience Insight Version13.5.1.0
OracleRest Data Services SwEdition- Version < 21.2
OracleRest Data Services Version21.3 SwEdition-
OracleRetail Integration Bus Version >= 16.0.1 <= 16.0.3
OracleRetail Integration Bus Version13.0
OracleRetail Integration Bus Version14.1.3.0
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.3.1
OracleRetail Integration Bus Version19.0.0
OracleRetail Integration Bus Version19.0.1
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleRetail Order Broker Version19.1
OracleRetail Pricing Version19.0.1
OracleRetail Service Backbone Version >= 16.0.1 <= 16.0.3
OracleRetail Service Backbone Version14.1.3.0
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version19.0.0
OracleRetail Service Backbone Version19.0.1
OracleSolaris Cluster Version4.0
OracleUtilities Testing Accelerator Version6.0.0.1.1
OracleUtilities Testing Accelerator Version6.0.0.2.2
OracleUtilities Testing Accelerator Version6.0.0.3.1
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
OracleWeblogic Server Version12.1.3.0.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
NetappActive Iq Unified Manager Version- SwPlatformlinux
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.644
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://issues.apache.org/jira/browse/IO-556
Vendor Advisory
Exploit
Issue Tracking