← Back

CVE-2020-9489

nvd nist
Published: Apr 27, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.

Affected (11)

1 product
Tika
4 products
Communications Messaging Server
Flexcube Private Banking
Primavera Unifier
Webcenter Portal
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.24
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.1
Oracle
Version 12.0.0
Version 12.1.0
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 19.12
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (10)

Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.