← Back

CVE-2021-29425

nvd nist
Published: Apr 13, 2021Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD

Description

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

Affected (136)

Products: Apache: Commons Io · Debian: Debian Linux · Oracle: Access Manager, Agile Engineering Data Management, Agile Plm, Application Performance Management, Application Testing Suite, Banking Apis, Banking Digital Experience, Banking Enterprise Default Management, Banking Enterprise Default Managment, Banking Party Management, Banking Platform, Blockchain Platform, Commerce Guided Search, Communications Application Session Controller, Communications Billing And Revenue Management Elastic Charging Engine, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Unified Data Repository, Communications Contacts Server, Communications Converged Application Server Service Controller, Communications Convergence, Communications Design Studio, Communications Diameter Intelligence Hub, Communications Interactive Session Recorder, Communications Offline Mediation Controller, Communications Order And Service Management, Communications Policy Management, Communications Pricing Design Center, Communications Service Broker, Enterprise Communications Broker, Enterprise Session Border Controller, Financial Services Analytical Applications Infrastructure, Financial Services Model Management And Governance, Flexcube Core Banking, Fusion Middleware Mapviewer, Health Sciences Data Management Workbench, Health Sciences Information Manager, Healthcare Data Repository, Helidon, Insurance Policy Administration, Insurance Rules Palette, Oss Support Tools, Primavera Unifier, Real User Experience Insight, Rest Data Services, Retail Assortment Planning, Retail Integration Bus, Retail Merchandising System, Retail Order Broker, Retail Pricing, Retail Service Backbone, Retail Size Profile Optimization, Retail Xstore Point Of Service, Solaris Cluster, Utilities Testing Accelerator, Webcenter Portal, Weblogic Server · +1 more
Show all products
Apache: Commons Io · Debian: Debian Linux · Oracle: Access Manager, Agile Engineering Data Management, Agile Plm, Application Performance Management, Application Testing Suite, Banking Apis, Banking Digital Experience, Banking Enterprise Default Management, Banking Enterprise Default Managment, Banking Party Management, Banking Platform, Blockchain Platform, Commerce Guided Search, Communications Application Session Controller, Communications Billing And Revenue Management Elastic Charging Engine, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Unified Data Repository, Communications Contacts Server, Communications Converged Application Server Service Controller, Communications Convergence, Communications Design Studio, Communications Diameter Intelligence Hub, Communications Interactive Session Recorder, Communications Offline Mediation Controller, Communications Order And Service Management, Communications Policy Management, Communications Pricing Design Center, Communications Service Broker, Enterprise Communications Broker, Enterprise Session Border Controller, Financial Services Analytical Applications Infrastructure, Financial Services Model Management And Governance, Flexcube Core Banking, Fusion Middleware Mapviewer, Health Sciences Data Management Workbench, Health Sciences Information Manager, Healthcare Data Repository, Helidon, Insurance Policy Administration, Insurance Rules Palette, Oss Support Tools, Primavera Unifier, Real User Experience Insight, Rest Data Services, Retail Assortment Planning, Retail Integration Bus, Retail Merchandising System, Retail Order Broker, Retail Pricing, Retail Service Backbone, Retail Size Profile Optimization, Retail Xstore Point Of Service, Solaris Cluster, Utilities Testing Accelerator, Webcenter Portal, Weblogic Server · Netapp: Active Iq Unified Manager
1 product
Commons Io
1 product
Debian Linux
57 products
Access Manager
Agile Engineering Data Management
Agile Plm
Application Testing Suite
Banking Apis
Banking Digital Experience
Banking Party Management
Banking Platform
Blockchain Platform
Commerce Guided Search
Communications Contacts Server
Communications Convergence
Communications Design Studio
Communications Policy Management
Communications Service Broker
Enterprise Communications Broker
Flexcube Core Banking
Fusion Middleware Mapviewer
Healthcare Data Repository
Helidon
Insurance Policy Administration
Insurance Rules Palette
Oss Support Tools
Primavera Unifier
Real User Experience Insight
Rest Data Services
Retail Assortment Planning
Retail Integration Bus
Retail Merchandising System
Retail Order Broker
Retail Pricing
Retail Service Backbone
Retail Size Profile Optimization
Retail Xstore Point Of Service
Solaris Cluster
Utilities Testing Accelerator
Webcenter Portal
Weblogic Server
1 product
Active Iq Unified Manager
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 2.2
Version 2.3
Version 2.4
Version 2.5
Version 2.6
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration C
127 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 11.1.2.3.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 6.2.1.0
Version 9.3.6
Oracle
Version 13.4.1.0
Version 13.5.1.0
Version 13.3.0.1
Oracle
Version 18.1
Version 18.2
Version 18.3
Version 19.1
Version 19.2
Version 20.1
Version 21.1
Oracle
Version 17.2
Version 18.1
Version 18.3
Version 19.1
Version 19.2
Version 20.1
Version 21.1
Oracle
Version 2.10.0
Version 2.12.0
Version 2.6.2
Version 2.7.0
Version 2.7.1
From 2.3.0 to 2.4.0
Version 2.7.0
Oracle
From 2.3.0 to 2.4.1
Version 2.6.2
Version 2.7.0
Version 2.7.1
Before 21.1.2
Version 11.3.2
Version 3.9.0
Oracle
Version 11.3
Version 12.0
Version 1.14.0
Version 1.14.0
Version 1.4.0
Version 8.0.0.6.0
Version 6.2
Version 3.0.2.2.0
Oracle
From 7.4.0 to 7.4.2
Version 7.3.5
Oracle
From 8.0.0 to 8.1.0
From 8.2.0 to 8.2.3
Oracle
Version 6.3
Version 6.4
Version 12.0.0.3
Oracle
Version 7.3
Version 7.4
Version 12.5.0.0.0
Oracle
Version 12.0.0.4.0
Version 12.0.0.5.0
Version 6.2
Version 3.3
Oracle
Version 8.4
Version 9.0
From 8.0.7 to 8.1.1
From 8.0.8 to 8.1.1
Oracle
From 11.6.0 to 11.8.0
Version 11.10.0
Version 5.2.0
Version 12.2.1.4.0
Oracle
Version 2.5.2.1
Version 3.0.0.0
From 3.0.1 to 3.0.4
Version 8.1.0
Oracle
Version 1.4.7
Version 2.2.0
Oracle
Version 11.0.2
Version 11.1.0
Version 11.2.8
Version 11.3.0
Version 11.3.1
Oracle
Version 11.0.2
Version 11.1.0
Version 11.2.8
Version 11.3.0
Version 11.3.1
Before 2.12.42
Oracle
From 17.7 to 17.12
Version 18.8
Version 19.12
Version 20.12
Version 21.12
Oracle
Version 13.4.1.0
Version 13.5.1.0
Oracle
Before 21.2
Version 21.3
Version 16.0.3
Oracle
From 16.0.1 to 16.0.3
Version 13.0
Version 14.1.3.0
Version 14.1.3.2
Version 15.0.3.1
Version 19.0.0
Version 19.0.1
Oracle
Version 16.0.3
Version 19.0.1
Oracle
Version 16.0
Version 18.0
Version 19.1
Version 19.0.1
Oracle
From 16.0.1 to 16.0.3
Version 14.1.3.0
Version 14.1.3.2
Version 15.0.3.1
Version 19.0.0
Version 19.0.1
Version 16.0.3
Oracle
Version 17.0.4
Version 18.0.3
Version 19.0.2
Version 20.0.1
Version 4.0
Oracle
Version 6.0.0.1.1
Version 6.0.0.2.2
Version 6.0.0.3.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions

References (94)

Source: security@apache.org
ExploitIssue TrackingVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.