CVE-2021-36373
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Affected (73)
Products: Apache: Ant · Oracle: Agile Plm, Banking Trade Finance, Banking Treasury Management, Communications Cloud Native Core Automated Test Suite, Communications Cloud Native Core Binding Support Function, Communications Order And Service Management, Communications Unified Inventory Management, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Insurance Policy Administration, Primavera Gateway, Primavera Unifier, Real Time Decision Server, Retail Advanced Inventory Planning, Retail Back Office, Retail Bulk Data Integration, Retail Central Office, Retail Eftlink, Retail Extract Transform And Load, Retail Financial Integration, Retail Integration Bus, Retail Invoice Matching, Retail Merchandising System, Retail Point Of Service, Retail Predictive Application Server, Retail Service Backbone, Retail Store Inventory Management, Retail Xstore Point Of Service, Timesten In Memory Database, Utilities Framework, Utilities Testing Accelerator
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.3.6 | |
| Version 14.5 | |
| Version 14.5 | |
| Version 1.9.0 | |
| Version 1.11.0 | |
| Version 7.3 | |
| Version 7.3.0 | |
| Version 11.1.1.7.0 | |
| From 8.0.6 to 8.1.1 | |
| From 11.0 to 11.3.1 | |
| From 17.12.0 to 17.12.11 | |
| From 17.7 to 17.12 | |
| Version 11.1.1.9.0 | |
| Version 14.1 | |
| Version 14.0 | |
| Version 16.0.3.0 | |
| Version 14.0 | |
| Version 19.0.1 | |
| Version 13.2.8 | |
| Version 14.1.3.2 | |
| Version 14.1.3.2 | |
| Version 16.0.3 | |
| Version 19.0.1 | |
| Version 14.0 | |
| Version 14.1.3 | |
| Version 14.1.3.2 | |
| Version 14.1 | |
| Version 16.0.6 | |
| Before 11.2.2.8.27 | |
| From 4.3.0.1.0 to 4.3.0.6.0 | |
| Version 6.0.0.1.1 |
References (22)
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.