Lucene search

K
nvd[email protected]NVD:CVE-2021-36373
HistoryJul 14, 2021 - 7:15 a.m.

CVE-2021-36373

2021-07-1407:15:08
CWE-130
web.nvd.nist.gov
7
cve-2021-36373
apache ant
memory allocation
tar archive
out of memory error
disruption
build

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

44.6%

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Affected configurations

Nvd
Node
apacheantRange1.9.01.9.16
OR
apacheantRange1.10.01.10.11
Node
oracleagile_plmMatch9.3.6
OR
oraclebanking_trade_financeMatch14.5
OR
oraclebanking_treasury_managementMatch14.5
OR
oraclecommunications_cloud_native_core_automated_test_suiteMatch1.9.0
OR
oraclecommunications_cloud_native_core_binding_support_functionMatch1.11.0
OR
oraclecommunications_order_and_service_managementMatch7.3
OR
oraclecommunications_order_and_service_managementMatch7.4
OR
oraclecommunications_unified_inventory_managementMatch7.3.0
OR
oraclecommunications_unified_inventory_managementMatch7.4.0
OR
oraclecommunications_unified_inventory_managementMatch7.4.1
OR
oraclecommunications_unified_inventory_managementMatch7.4.2
OR
oraclecommunications_unified_inventory_managementMatch7.5.0
OR
oracleenterprise_repositoryMatch11.1.1.7.0
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.68.1.1
OR
oracleinsurance_policy_administrationRange11.011.3.1
OR
oracleprimavera_gatewayRange17.12.017.12.11
OR
oracleprimavera_gatewayRange18.8.018.8.12
OR
oracleprimavera_gatewayRange19.12.019.12.11
OR
oracleprimavera_gatewayRange20.12.020.12.7
OR
oracleprimavera_unifierRange17.717.12
OR
oracleprimavera_unifierMatch18.8
OR
oracleprimavera_unifierMatch19.12
OR
oracleprimavera_unifierMatch20.12
OR
oraclereal-time_decision_serverMatch3.2.0.0
OR
oraclereal-time_decision_serverMatch11.1.1.9.0
OR
oracleretail_advanced_inventory_planningMatch14.1
OR
oracleretail_advanced_inventory_planningMatch15.0
OR
oracleretail_advanced_inventory_planningMatch16.0
OR
oracleretail_back_officeMatch14.0
OR
oracleretail_back_officeMatch14.1
OR
oracleretail_bulk_data_integrationMatch16.0.3.0
OR
oracleretail_bulk_data_integrationMatch19.0.1
OR
oracleretail_central_officeMatch14.0
OR
oracleretail_central_officeMatch14.1
OR
oracleretail_eftlinkMatch19.0.1
OR
oracleretail_eftlinkMatch20.0.1
OR
oracleretail_extract_transform_and_loadMatch13.2.8
OR
oracleretail_financial_integrationMatch14.1.3.2
OR
oracleretail_financial_integrationMatch15.0.4.0
OR
oracleretail_financial_integrationMatch16.0.3.0
OR
oracleretail_integration_busMatch14.1.3.2
OR
oracleretail_integration_busMatch15.0.4.0
OR
oracleretail_integration_busMatch16.0.3.0
OR
oracleretail_integration_busMatch19.0.1.0
OR
oracleretail_invoice_matchingMatch16.0.3
OR
oracleretail_merchandising_systemMatch19.0.1
OR
oracleretail_point-of-serviceMatch14.0
OR
oracleretail_point-of-serviceMatch14.1
OR
oracleretail_predictive_application_serverMatch14.1.3
OR
oracleretail_predictive_application_serverMatch15.0.3
OR
oracleretail_predictive_application_serverMatch16.0.3.0
OR
oracleretail_service_backboneMatch14.1.3.2
OR
oracleretail_service_backboneMatch15.0.4.0
OR
oracleretail_service_backboneMatch16.0.3.0
OR
oracleretail_service_backboneMatch19.0.1.0
OR
oracleretail_store_inventory_managementMatch14.1
OR
oracleretail_store_inventory_managementMatch15.0
OR
oracleretail_store_inventory_managementMatch16.0
OR
oracleretail_xstore_point_of_serviceMatch16.0.6
OR
oracleretail_xstore_point_of_serviceMatch17.0.4
OR
oracleretail_xstore_point_of_serviceMatch18.0.3
OR
oracleretail_xstore_point_of_serviceMatch19.0.2
OR
oracleretail_xstore_point_of_serviceMatch20.0.1
OR
oracletimesten_in-memory_databaseRange<11.2.2.8.27
OR
oracleutilities_frameworkRange4.3.0.1.04.3.0.6.0
OR
oracleutilities_frameworkMatch4.2.0.2.0
OR
oracleutilities_frameworkMatch4.2.0.3.0
OR
oracleutilities_frameworkMatch4.4.0.0.0
OR
oracleutilities_frameworkMatch4.4.0.2.0
OR
oracleutilities_frameworkMatch4.4.0.3.0
OR
oracleutilities_testing_acceleratorMatch6.0.0.1.1
VendorProductVersionCPE
apacheant*cpe:2.3:a:apache:ant:*:*:*:*:*:*:*:*
oracleagile_plm9.3.6cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
oraclebanking_trade_finance14.5cpe:2.3:a:oracle:banking_trade_finance:14.5:*:*:*:*:*:*:*
oraclebanking_treasury_management14.5cpe:2.3:a:oracle:banking_treasury_management:14.5:*:*:*:*:*:*:*
oraclecommunications_cloud_native_core_automated_test_suite1.9.0cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
oraclecommunications_cloud_native_core_binding_support_function1.11.0cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*
oraclecommunications_order_and_service_management7.3cpe:2.3:a:oracle:communications_order_and_service_management:7.3:*:*:*:*:*:*:*
oraclecommunications_order_and_service_management7.4cpe:2.3:a:oracle:communications_order_and_service_management:7.4:*:*:*:*:*:*:*
oraclecommunications_unified_inventory_management7.3.0cpe:2.3:a:oracle:communications_unified_inventory_management:7.3.0:*:*:*:*:*:*:*
oraclecommunications_unified_inventory_management7.4.0cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 691

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

44.6%