7.5

CVE-2021-36090

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

Data is provided by the National Vulnerability Database (NVD)
ApacheCommons Compress Version >= 1.0 < 1.21
OracleBanking Apis Version >= 18.1 <= 18.3
OracleBanking Apis Version19.1
OracleBanking Apis Version19.2
OracleBanking Apis Version20.1
OracleBanking Apis Version21.1
OracleBanking Digital Experience Version >= 18.1 <= 18.3
OracleBanking Party Management Version2.7.0
OracleBanking Payments Version14.5
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.9.0
OracleBanking Platform Version2.12.0
OracleBanking Trade Finance Version14.5
OracleCommerce Guided Search Version11.3.2
OracleCommunications Diameter Intelligence Hub Version >= 8.0.0 <= 8.2.3
OracleCommunications Element Manager Version >= 8.2.0 <= 8.2.4.0
OracleCommunications Session Report Manager Version >= 8.2.0 <= 8.2.5.0
OracleCommunications Session Route Manager Version >= 8.0.0 <= 8.2.5.0
OracleFlexcube Universal Banking Version >= 14.0.0 <= 14.3.0
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.12
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.11
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OracleUtilities Testing Accelerator Version6.0.0.1.1
OracleUtilities Testing Accelerator Version6.0.0.2.2
OracleUtilities Testing Accelerator Version6.0.0.3.1
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
NetappActive Iq Unified Manager Version- SwPlatformlinux
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappOncommand Insight Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.483
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-130 Improper Handling of Length Parameter Inconsistency

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.