5.5

CVE-2021-36374

Apache Ant ZIP, and ZIP based, archive denial of service vulerability

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Ant Version >= 1.9.0 < 1.9.16
Apache ≫ Ant Version >= 1.10.0 < 1.10.11
Oracle ≫ Banking Trade Finance Version 14.5
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
Oracle ≫ Communications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
Oracle ≫ Enterprise Repository Version 11.1.1.7.0
Oracle ≫ Health Sciences Information Manager Version >= 3.0.1 <= 3.0.5
Oracle ≫ Insurance Policy Administration Version >= 11.0 <= 11.3.1
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.11
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.12
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.11
Oracle ≫ Primavera Gateway Version >= 20.12.0 <= 20.12.7
Oracle ≫ Primavera Unifier Version >= 17.7 <= 17.12
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Primavera Unifier Version 19.12
Oracle ≫ Primavera Unifier Version 20.12
Oracle ≫ Real-time Decision Server Version 3.2.0.0
Oracle ≫ Real-time Decision Server Version 11.1.1.9.0
Oracle ≫ Retail Back Office Version 14.0
Oracle ≫ Retail Back Office Version 14.1
Oracle ≫ Retail Bulk Data Integration Version 16.0.3.0
Oracle ≫ Retail Central Office Version 14.0
Oracle ≫ Retail Central Office Version 14.1
Oracle ≫ Retail Eftlink Version 19.0.1
Oracle ≫ Retail Eftlink Version 20.0.1
Oracle ≫ Retail Financial Integration Version 14.1.3.2
Oracle ≫ Retail Financial Integration Version 15.0.4.0
Oracle ≫ Retail Financial Integration Version 16.0.3.0
Oracle ≫ Retail Integration Bus Version 14.1.3.2
Oracle ≫ Retail Integration Bus Version 15.0.4.0
Oracle ≫ Retail Integration Bus Version 16.0.3.0
Oracle ≫ Retail Integration Bus Version 19.0.1.0
Oracle ≫ Retail Invoice Matching Version 16.0.3
Oracle ≫ Retail Merchandising System Version 19.0.1
Oracle ≫ Retail Point-of-service Version 14.0
Oracle ≫ Retail Point-of-service Version 14.1
Oracle ≫ Retail Service Backbone Version 14.1.3.2
Oracle ≫ Retail Service Backbone Version 15.0.4.0
Oracle ≫ Retail Service Backbone Version 16.0.3.0
Oracle ≫ Retail Service Backbone Version 19.0.1.0
Oracle ≫ Timesten In-memory Database Version < 11.2.2.8.27
Oracle ≫ Utilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
Oracle ≫ Utilities Framework Version 4.2.0.2.0
Oracle ≫ Utilities Framework Version 4.2.0.3.0
Oracle ≫ Utilities Framework Version 4.4.0.0.0
Oracle ≫ Utilities Framework Version 4.4.0.2.0
Oracle ≫ Utilities Framework Version 4.4.0.3.0
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.64% 0.84
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-130 Improper Handling of Length Parameter Inconsistency

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://ant.apache.org/security.html
Patch
Vendor Advisory
https://security.netapp.com/advisory/ntap-20210819-0007/
Third Party Advisory
https://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a%40%3Ccommits.groovy.apache.org%3E
https://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d%40%3Ccommits.groovy.apache.org%3E
https://lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6444e373a%40%3Cnotifications.groovy.apache.org%3E
https://lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91395a96c6%40%3Cdev.myfaces.apache.org%3E
https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3E
Vendor Advisory
Mailing List