← Back

CVE-2021-36374

nvd nist
Published: Jul 14, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Affected (79)

Products: Apache: Ant · Oracle: Agile Engineering Data Management, Agile Plm, Banking Trade Finance, Banking Treasury Management, Communications Cloud Native Core Automated Test Suite, Communications Cloud Native Core Binding Support Function, Communications Diameter Intelligence Hub, Communications Order And Service Management, Communications Unified Inventory Management, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Health Sciences Information Manager, Insurance Policy Administration, Primavera Gateway, Primavera Unifier, Product Lifecycle Analytics, Real Time Decision Server, Retail Advanced Inventory Planning, Retail Back Office, Retail Bulk Data Integration, Retail Central Office, Retail Eftlink, Retail Extract Transform And Load, Retail Financial Integration, Retail Integration Bus, Retail Invoice Matching, Retail Merchandising System, Retail Point Of Service, Retail Predictive Application Server, Retail Service Backbone, Retail Store Inventory Management, Retail Xstore Point Of Service, Timesten In Memory Database, Utilities Framework, Utilities Testing Accelerator
1 product
Ant
35 products
Agile Engineering Data Management
Agile Plm
Banking Trade Finance
Banking Treasury Management
Enterprise Repository
Insurance Policy Administration
Primavera Gateway
Primavera Unifier
Product Lifecycle Analytics
Real Time Decision Server
Retail Back Office
Retail Bulk Data Integration
Retail Central Office
Retail Eftlink
Retail Extract Transform And Load
Retail Financial Integration
Retail Integration Bus
Retail Invoice Matching
Retail Merchandising System
Retail Point Of Service
Retail Service Backbone
Retail Store Inventory Management
Retail Xstore Point Of Service
Timesten In Memory Database
Utilities Framework
Utilities Testing Accelerator
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.10.0 to 1.10.11
From 1.9.0 to 1.9.16
Configuration B
77 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2.1.0
Version 9.3.6
Version 14.5
Version 14.5
Version 1.9.0
Version 1.11.0
Oracle
From 8.0.0 to 8.1.0
From 8.2.0 to 8.2.3
Oracle
Version 7.3
Version 7.4
Oracle
Version 7.3.0
Version 7.4.0
Version 7.4.1
Version 7.4.2
Version 7.5.0
Version 11.1.1.7.0
From 8.0.6 to 8.1.1
Oracle
From 3.0.1 to 3.0.5
Version 3.0.0.1
From 11.0 to 11.3.1
Oracle
From 17.12.0 to 17.12.11
From 18.8.0 to 18.8.12
From 19.12.0 to 19.12.11
From 20.12.0 to 20.12.7
Oracle
From 17.7 to 17.12
Version 18.8
Version 19.12
Version 20.12
Version 3.6.1
Oracle
Version 11.1.1.9.0
Version 3.2.0.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 14.0
Version 14.1
Oracle
Version 16.0.3.0
Version 19.0.1
Oracle
Version 14.0
Version 14.1
Oracle
Version 19.0.1
Version 20.0.1
Version 13.2.8
Oracle
Version 14.1.3.2
Version 15.0.4.0
Version 16.0.3.0
Oracle
Version 14.1.3.2
Version 15.0.4.0
Version 16.0.3.0
Version 19.0.1.0
Version 16.0.3
Version 19.0.1
Oracle
Version 14.0
Version 14.1
Oracle
Version 14.1.3
Version 15.0.3
Version 16.0.3.0
Oracle
Version 14.1.3.2
Version 15.0.4.0
Version 16.0.3.0
Version 19.0.1.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 16.0.6
Version 17.0.4
Version 18.0.3
Version 19.0.2
Version 20.0.1
Before 11.2.2.8.27
Oracle
From 4.3.0.1.0 to 4.3.0.6.0
Version 4.2.0.2.0
Version 4.2.0.3.0
Version 4.4.0.0.0
Version 4.4.0.2.0
Version 4.4.0.3.0
Version 6.0.0.1.1

References (22)

Source: security@apache.org
PatchVendor Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.