Lucene search

K
cveApacheCVE-2021-41973
HistoryNov 01, 2021 - 9:15 a.m.

CVE-2021-41973

2021-11-0109:15:09
CWE-835
apache
web.nvd.nist.gov
95
apache mina
cve-2021-41973
http header
decoder
nvd
security update

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.6

Confidence

High

EPSS

0.004

Percentile

74.9%

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

Affected configurations

Nvd
Vulners
Node
apacheminaRange<2.0.22
OR
apacheminaRange2.1.02.1.5
Node
oraclebanking_paymentsMatch14.5
OR
oraclebanking_trade_finance_process_managementMatch14.5
OR
oraclebanking_treasury_managementMatch14.5
OR
oraclecommunications_cloud_native_core_consoleMatch1.9.0
OR
oraclecustomer_management_and_segmentation_foundationMatch18.0
OR
oraclecustomer_management_and_segmentation_foundationMatch19.0
OR
oracleflexcube_universal_bankingRange14.014.3
OR
oracleflexcube_universal_bankingMatch14.5
OR
oraclefusion_middleware_common_libraries_and_toolsMatch12.2.1.3.0
OR
oraclefusion_middleware_common_libraries_and_toolsMatch12.2.1.4.0
OR
oraclefusion_middleware_common_libraries_and_toolsMatch14.1.1.0.0
OR
oracleoss_support_toolsMatch2.12.42
VendorProductVersionCPE
apachemina*cpe:2.3:a:apache:mina:*:*:*:*:*:*:*:*
oraclebanking_payments14.5cpe:2.3:a:oracle:banking_payments:14.5:*:*:*:*:*:*:*
oraclebanking_trade_finance_process_management14.5cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5:*:*:*:*:*:*:*
oraclebanking_treasury_management14.5cpe:2.3:a:oracle:banking_treasury_management:14.5:*:*:*:*:*:*:*
oraclecommunications_cloud_native_core_console1.9.0cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
oraclecustomer_management_and_segmentation_foundation18.0cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*
oraclecustomer_management_and_segmentation_foundation19.0cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*
oracleflexcube_universal_banking*cpe:2.3:a:oracle:flexcube_universal_banking:*:*:*:*:*:*:*:*
oracleflexcube_universal_banking14.5cpe:2.3:a:oracle:flexcube_universal_banking:14.5:*:*:*:*:*:*:*
oraclefusion_middleware_common_libraries_and_tools12.2.1.3.0cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:12.2.1.3.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CNA Affected

[
  {
    "product": "Apache MINA",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "changes": [
          {
            "at": "2.0.22",
            "status": "unaffected"
          }
        ],
        "lessThan": "2.1.5",
        "status": "affected",
        "version": "Apache MINA",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.6

Confidence

High

EPSS

0.004

Percentile

74.9%