CVE-2021-37136
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
Affected (38)
Products: Netty: Netty · Quarkus: Quarkus · Oracle: Banking Apis, Banking Digital Experience, Coherence, Commerce Guided Search, Communications Brm Elastic Charging Engine, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Unified Data Repository, Communications Diameter Signaling Router, Communications Instant Messaging Server, Helidon, Peoplesoft Enterprise Peopletools, Webcenter Portal · +2 more
Show all products
Netty: Netty · Quarkus: Quarkus · Oracle: Banking Apis, Banking Digital Experience, Coherence, Commerce Guided Search, Communications Brm Elastic Charging Engine, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Policy, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Unified Data Repository, Communications Diameter Signaling Router, Communications Instant Messaging Server, Helidon, Peoplesoft Enterprise Peopletools, Webcenter Portal · Netapp: Oncommand Insight · Debian: Debian Linux
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.1 to 18.3 | |
| Version 18.1 | |
| Version 12.2.1.4.0 | |
| Version 11.3.2 | |
| Before 12.0.0.4.6 | |
| Version 1.10.0 | |
| Version 1.8.0 | |
| Version 1.15.0 | |
| Version 1.7.0 | |
| Version 1.15.0 | |
| From 8.0.0.0 to 8.5.0.2 | |
| Version 8.1 | |
| Version 1.4.10 | |
| Version 8.48 | |
| Version 12.2.1.3.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
References (26)
Source: reefs@jfrog.com
Third Party Advisory
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Mailing ListThird Party Advisory
Source: reefs@jfrog.com
PatchThird Party Advisory
Source: reefs@jfrog.com
PatchThird Party Advisory
Source: reefs@jfrog.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.