5.5

CVE-2021-36374

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheAnt Version >= 1.9.0 < 1.9.16
ApacheAnt Version >= 1.10.0 < 1.10.11
OracleAgile Plm Version9.3.6
OracleBanking Trade Finance Version14.5
OracleCommunications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
OracleCommunications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
OracleEnterprise Repository Version11.1.1.7.0
OracleHealth Sciences Information Manager Version >= 3.0.1 <= 3.0.5
OracleInsurance Policy Administration Version >= 11.0 <= 11.3.1
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.12
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.11
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OracleReal-time Decision Server Version3.2.0.0
OracleReal-time Decision Server Version11.1.1.9.0
OracleRetail Back Office Version14.0
OracleRetail Back Office Version14.1
OracleRetail Bulk Data Integration Version16.0.3.0
OracleRetail Central Office Version14.0
OracleRetail Central Office Version14.1
OracleRetail Eftlink Version19.0.1
OracleRetail Eftlink Version20.0.1
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.4.0
OracleRetail Financial Integration Version16.0.3.0
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.4.0
OracleRetail Integration Bus Version16.0.3.0
OracleRetail Integration Bus Version19.0.1.0
OracleRetail Invoice Matching Version16.0.3
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.4.0
OracleRetail Service Backbone Version16.0.3.0
OracleRetail Service Backbone Version19.0.1.0
OracleTimesten In-memory Database Version < 11.2.2.8.27
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleUtilities Testing Accelerator Version6.0.0.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.398
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-130 Improper Handling of Length Parameter Inconsistency

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.