Lucene search

K
nvd[email protected]NVD:CVE-2021-36374
HistoryJul 14, 2021 - 7:15 a.m.

CVE-2021-36374

2021-07-1407:15:08
CWE-130
web.nvd.nist.gov
3

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

31.7%

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Affected configurations

NVD
Node
apacheantRange1.9.01.9.16
OR
apacheantRange1.10.01.10.11
Node
oracleagile_engineering_data_managementMatch6.2.1.0
OR
oracleagile_plmMatch9.3.6
OR
oraclebanking_trade_financeMatch14.5
OR
oraclebanking_treasury_managementMatch14.5
OR
oraclecommunications_cloud_native_core_automated_test_suiteMatch1.9.0
OR
oraclecommunications_cloud_native_core_binding_support_functionMatch1.11.0
OR
oraclecommunications_diameter_intelligence_hubRange8.0.08.1.0
OR
oraclecommunications_diameter_intelligence_hubRange8.2.08.2.3
OR
oraclecommunications_order_and_service_managementMatch7.3
OR
oraclecommunications_order_and_service_managementMatch7.4
OR
oraclecommunications_unified_inventory_managementMatch7.3.0
OR
oraclecommunications_unified_inventory_managementMatch7.4.0
OR
oraclecommunications_unified_inventory_managementMatch7.4.1
OR
oraclecommunications_unified_inventory_managementMatch7.4.2
OR
oraclecommunications_unified_inventory_managementMatch7.5.0
OR
oracleenterprise_repositoryMatch11.1.1.7.0
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.68.1.1
OR
oraclehealth_sciences_information_managerRange3.0.13.0.5
OR
oraclehealth_sciences_information_managerMatch3.0.0.1
OR
oracleinsurance_policy_administrationRange11.011.3.1
OR
oracleprimavera_gatewayRange17.12.017.12.11
OR
oracleprimavera_gatewayRange18.8.018.8.12
OR
oracleprimavera_gatewayRange19.12.019.12.11
OR
oracleprimavera_gatewayRange20.12.020.12.7
OR
oracleprimavera_unifierRange17.717.12
OR
oracleprimavera_unifierMatch18.8
OR
oracleprimavera_unifierMatch19.12
OR
oracleprimavera_unifierMatch20.12
OR
oracleproduct_lifecycle_analyticsMatch3.6.1
OR
oraclereal-time_decision_serverMatch3.2.0.0
OR
oraclereal-time_decision_serverMatch11.1.1.9.0
OR
oracleretail_advanced_inventory_planningMatch14.1
OR
oracleretail_advanced_inventory_planningMatch15.0
OR
oracleretail_advanced_inventory_planningMatch16.0
OR
oracleretail_back_officeMatch14.0
OR
oracleretail_back_officeMatch14.1
OR
oracleretail_bulk_data_integrationMatch16.0.3.0
OR
oracleretail_bulk_data_integrationMatch19.0.1
OR
oracleretail_central_officeMatch14.0
OR
oracleretail_central_officeMatch14.1
OR
oracleretail_eftlinkMatch19.0.1
OR
oracleretail_eftlinkMatch20.0.1
OR
oracleretail_extract_transform_and_loadMatch13.2.8
OR
oracleretail_financial_integrationMatch14.1.3.2
OR
oracleretail_financial_integrationMatch15.0.4.0
OR
oracleretail_financial_integrationMatch16.0.3.0
OR
oracleretail_integration_busMatch14.1.3.2
OR
oracleretail_integration_busMatch15.0.4.0
OR
oracleretail_integration_busMatch16.0.3.0
OR
oracleretail_integration_busMatch19.0.1.0
OR
oracleretail_invoice_matchingMatch16.0.3
OR
oracleretail_merchandising_systemMatch19.0.1
OR
oracleretail_point-of-serviceMatch14.0
OR
oracleretail_point-of-serviceMatch14.1
OR
oracleretail_predictive_application_serverMatch14.1.3
OR
oracleretail_predictive_application_serverMatch15.0.3
OR
oracleretail_predictive_application_serverMatch16.0.3.0
OR
oracleretail_service_backboneMatch14.1.3.2
OR
oracleretail_service_backboneMatch15.0.4.0
OR
oracleretail_service_backboneMatch16.0.3.0
OR
oracleretail_service_backboneMatch19.0.1.0
OR
oracleretail_store_inventory_managementMatch14.1
OR
oracleretail_store_inventory_managementMatch15.0
OR
oracleretail_store_inventory_managementMatch16.0
OR
oracleretail_xstore_point_of_serviceMatch16.0.6
OR
oracleretail_xstore_point_of_serviceMatch17.0.4
OR
oracleretail_xstore_point_of_serviceMatch18.0.3
OR
oracleretail_xstore_point_of_serviceMatch19.0.2
OR
oracleretail_xstore_point_of_serviceMatch20.0.1
OR
oracletimesten_in-memory_databaseRange<11.2.2.8.27
OR
oracleutilities_frameworkRange4.3.0.1.04.3.0.6.0
OR
oracleutilities_frameworkMatch4.2.0.2.0
OR
oracleutilities_frameworkMatch4.2.0.3.0
OR
oracleutilities_frameworkMatch4.4.0.0.0
OR
oracleutilities_frameworkMatch4.4.0.2.0
OR
oracleutilities_frameworkMatch4.4.0.3.0
OR
oracleutilities_testing_acceleratorMatch6.0.0.1.1

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

31.7%