5.5

CVE-2021-36373

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheAnt Version >= 1.9.0 < 1.9.16
ApacheAnt Version >= 1.10.0 < 1.10.11
OracleAgile Plm Version9.3.6
OracleBanking Trade Finance Version14.5
OracleEnterprise Repository Version11.1.1.7.0
OracleInsurance Policy Administration Version >= 11.0 <= 11.3.1
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.12
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.11
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OracleReal-time Decision Server Version3.2.0.0
OracleReal-time Decision Server Version11.1.1.9.0
OracleRetail Back Office Version14.0
OracleRetail Back Office Version14.1
OracleRetail Bulk Data Integration Version16.0.3.0
OracleRetail Central Office Version14.0
OracleRetail Central Office Version14.1
OracleRetail Eftlink Version19.0.1
OracleRetail Eftlink Version20.0.1
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.4.0
OracleRetail Financial Integration Version16.0.3.0
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.4.0
OracleRetail Integration Bus Version16.0.3.0
OracleRetail Integration Bus Version19.0.1.0
OracleRetail Invoice Matching Version16.0.3
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.4.0
OracleRetail Service Backbone Version16.0.3.0
OracleRetail Service Backbone Version19.0.1.0
OracleTimesten In-memory Database Version < 11.2.2.8.27
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleUtilities Testing Accelerator Version6.0.0.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-130 Improper Handling of Length Parameter Inconsistency

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.