CVE-2021-29425
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD
Description
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Affected (136)
Products: Apache: Commons Io · Debian: Debian Linux · Oracle: Access Manager, Agile Engineering Data Management, Agile Plm, Application Performance Management, Application Testing Suite, Banking Apis, Banking Digital Experience, Banking Enterprise Default Management, Banking Enterprise Default Managment, Banking Party Management, Banking Platform, Blockchain Platform, Commerce Guided Search, Communications Application Session Controller, Communications Billing And Revenue Management Elastic Charging Engine, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Unified Data Repository, Communications Contacts Server, Communications Converged Application Server Service Controller, Communications Convergence, Communications Design Studio, Communications Diameter Intelligence Hub, Communications Interactive Session Recorder, Communications Offline Mediation Controller, Communications Order And Service Management, Communications Policy Management, Communications Pricing Design Center, Communications Service Broker, Enterprise Communications Broker, Enterprise Session Border Controller, Financial Services Analytical Applications Infrastructure, Financial Services Model Management And Governance, Flexcube Core Banking, Fusion Middleware Mapviewer, Health Sciences Data Management Workbench, Health Sciences Information Manager, Healthcare Data Repository, Helidon, Insurance Policy Administration, Insurance Rules Palette, Oss Support Tools, Primavera Unifier, Real User Experience Insight, Rest Data Services, Retail Assortment Planning, Retail Integration Bus, Retail Merchandising System, Retail Order Broker, Retail Pricing, Retail Service Backbone, Retail Size Profile Optimization, Retail Xstore Point Of Service, Solaris Cluster, Utilities Testing Accelerator, Webcenter Portal, Weblogic Server · +1 more
Show all products
Apache: Commons Io · Debian: Debian Linux · Oracle: Access Manager, Agile Engineering Data Management, Agile Plm, Application Performance Management, Application Testing Suite, Banking Apis, Banking Digital Experience, Banking Enterprise Default Management, Banking Enterprise Default Managment, Banking Party Management, Banking Platform, Blockchain Platform, Commerce Guided Search, Communications Application Session Controller, Communications Billing And Revenue Management Elastic Charging Engine, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Unified Data Repository, Communications Contacts Server, Communications Converged Application Server Service Controller, Communications Convergence, Communications Design Studio, Communications Diameter Intelligence Hub, Communications Interactive Session Recorder, Communications Offline Mediation Controller, Communications Order And Service Management, Communications Policy Management, Communications Pricing Design Center, Communications Service Broker, Enterprise Communications Broker, Enterprise Session Border Controller, Financial Services Analytical Applications Infrastructure, Financial Services Model Management And Governance, Flexcube Core Banking, Fusion Middleware Mapviewer, Health Sciences Data Management Workbench, Health Sciences Information Manager, Healthcare Data Repository, Helidon, Insurance Policy Administration, Insurance Rules Palette, Oss Support Tools, Primavera Unifier, Real User Experience Insight, Rest Data Services, Retail Assortment Planning, Retail Integration Bus, Retail Merchandising System, Retail Order Broker, Retail Pricing, Retail Service Backbone, Retail Size Profile Optimization, Retail Xstore Point Of Service, Solaris Cluster, Utilities Testing Accelerator, Webcenter Portal, Weblogic Server · Netapp: Active Iq Unified Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.2.3.0 | |
| Version 6.2.1.0 | |
| Version 9.3.6 | |
| Version 13.4.1.0 | |
| Version 13.3.0.1 | |
| Version 18.1 | |
| Version 17.2 | |
| Version 2.10.0 | |
| From 2.3.0 to 2.4.0 | |
| Version 2.7.0 | |
| From 2.3.0 to 2.4.1 | |
| Before 21.1.2 | |
| Version 11.3.2 | |
| Version 3.9.0 | |
| Version 11.3 | |
| Version 1.14.0 | |
| Version 1.14.0 | |
| Version 1.4.0 | |
| Version 8.0.0.6.0 | |
| Version 6.2 | |
| Version 3.0.2.2.0 | |
| From 7.4.0 to 7.4.2 | |
| From 8.0.0 to 8.1.0 | |
| Version 6.3 | |
| Version 12.0.0.3 | |
| Version 7.3 | |
| Version 12.5.0.0.0 | |
| Version 12.0.0.4.0 | |
| Version 6.2 | |
| Version 3.3 | |
| Version 8.4 | |
| From 8.0.7 to 8.1.1 | |
| From 8.0.8 to 8.1.1 | |
| From 11.6.0 to 11.8.0 | |
| Version 12.2.1.4.0 | |
| Version 2.5.2.1 | |
| From 3.0.1 to 3.0.4 | |
| Version 8.1.0 | |
| Version 1.4.7 | |
| Version 11.0.2 | |
| Version 11.0.2 | |
| Before 2.12.42 | |
| From 17.7 to 17.12 | |
| Version 13.4.1.0 | |
| Before 21.2 | |
| Version 16.0.3 | |
| From 16.0.1 to 16.0.3 | |
| Version 16.0.3 | |
| Version 16.0 | |
| Version 19.0.1 | |
| From 16.0.1 to 16.0.3 | |
| Version 16.0.3 | |
| Version 17.0.4 | |
| Version 4.0 | |
| Version 6.0.0.1.1 | |
| Version 12.2.1.3.0 | |
| Version 12.1.3.0.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
References (94)
Source: security@apache.org
ExploitIssue TrackingVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.