// For flags

CVE-2021-36373

Apache Ant TAR archive denial of service vulnerability

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Cuando se lee un archivo TAR especialmente diseñado, se puede hacer que una compilación de Apache Ant asigne grandes cantidades de memoria que finalmente conlleva a un error de falta de memoria, incluso para entradas pequeñas. Esto puede ser usado para interrumpir las compilaciones usando Apache Ant. Apache Ant versiones anteriores a 1.9.16 y 1.10.11 estaban afectados

*Credits: This issue is similar to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35517 present in Apache Commons Compress which has been detected by OSS Fuzz.
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-12 CVE Reserved
  • 2021-07-14 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-09-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-130: Improper Handling of Length Parameter Inconsistency
  • CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Ant
Search vendor "Apache" for product "Ant"
>= 1.9.0 < 1.9.16
Search vendor "Apache" for product "Ant" and version " >= 1.9.0 < 1.9.16"
-
Affected
Apache
Search vendor "Apache"
Ant
Search vendor "Apache" for product "Ant"
>= 1.10.0 < 1.10.11
Search vendor "Apache" for product "Ant" and version " >= 1.10.0 < 1.10.11"
-
Affected
Oracle
Search vendor "Oracle"
Agile Plm
Search vendor "Oracle" for product "Agile Plm"
9.3.6
Search vendor "Oracle" for product "Agile Plm" and version "9.3.6"
-
Affected
Oracle
Search vendor "Oracle"
Banking Trade Finance
Search vendor "Oracle" for product "Banking Trade Finance"
14.5
Search vendor "Oracle" for product "Banking Trade Finance" and version "14.5"
-
Affected
Oracle
Search vendor "Oracle"
Banking Treasury Management
Search vendor "Oracle" for product "Banking Treasury Management"
14.5
Search vendor "Oracle" for product "Banking Treasury Management" and version "14.5"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Automated Test Suite
Search vendor "Oracle" for product "Communications Cloud Native Core Automated Test Suite"
1.9.0
Search vendor "Oracle" for product "Communications Cloud Native Core Automated Test Suite" and version "1.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Binding Support Function
Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function"
1.11.0
Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function" and version "1.11.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Order And Service Management
Search vendor "Oracle" for product "Communications Order And Service Management"
7.3
Search vendor "Oracle" for product "Communications Order And Service Management" and version "7.3"
-
Affected
Oracle
Search vendor "Oracle"
Communications Order And Service Management
Search vendor "Oracle" for product "Communications Order And Service Management"
7.4
Search vendor "Oracle" for product "Communications Order And Service Management" and version "7.4"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.3.0
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.4.0
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.4.1
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.4.2
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.5.0
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Repository
Search vendor "Oracle" for product "Enterprise Repository"
11.1.1.7.0
Search vendor "Oracle" for product "Enterprise Repository" and version "11.1.1.7.0"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Analytical Applications Infrastructure
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure"
>= 8.0.6 <= 8.1.1
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.0.6 <= 8.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Policy Administration
Search vendor "Oracle" for product "Insurance Policy Administration"
>= 11.0 <= 11.3.1
Search vendor "Oracle" for product "Insurance Policy Administration" and version " >= 11.0 <= 11.3.1"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
>= 17.12.0 <= 17.12.11
Search vendor "Oracle" for product "Primavera Gateway" and version " >= 17.12.0 <= 17.12.11"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
>= 18.8.0 <= 18.8.12
Search vendor "Oracle" for product "Primavera Gateway" and version " >= 18.8.0 <= 18.8.12"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
>= 19.12.0 <= 19.12.11
Search vendor "Oracle" for product "Primavera Gateway" and version " >= 19.12.0 <= 19.12.11"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Gateway
Search vendor "Oracle" for product "Primavera Gateway"
>= 20.12.0 <= 20.12.7
Search vendor "Oracle" for product "Primavera Gateway" and version " >= 20.12.0 <= 20.12.7"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
>= 17.7 <= 17.12
Search vendor "Oracle" for product "Primavera Unifier" and version " >= 17.7 <= 17.12"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
18.8
Search vendor "Oracle" for product "Primavera Unifier" and version "18.8"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
19.12
Search vendor "Oracle" for product "Primavera Unifier" and version "19.12"
-
Affected
Oracle
Search vendor "Oracle"
Primavera Unifier
Search vendor "Oracle" for product "Primavera Unifier"
20.12
Search vendor "Oracle" for product "Primavera Unifier" and version "20.12"
-
Affected
Oracle
Search vendor "Oracle"
Real-time Decision Server
Search vendor "Oracle" for product "Real-time Decision Server"
3.2.0.0
Search vendor "Oracle" for product "Real-time Decision Server" and version "3.2.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Real-time Decision Server
Search vendor "Oracle" for product "Real-time Decision Server"
11.1.1.9.0
Search vendor "Oracle" for product "Real-time Decision Server" and version "11.1.1.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Advanced Inventory Planning
Search vendor "Oracle" for product "Retail Advanced Inventory Planning"
14.1
Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Advanced Inventory Planning
Search vendor "Oracle" for product "Retail Advanced Inventory Planning"
15.0
Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Advanced Inventory Planning
Search vendor "Oracle" for product "Retail Advanced Inventory Planning"
16.0
Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
14.0
Search vendor "Oracle" for product "Retail Back Office" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
14.1
Search vendor "Oracle" for product "Retail Back Office" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Bulk Data Integration
Search vendor "Oracle" for product "Retail Bulk Data Integration"
16.0.3.0
Search vendor "Oracle" for product "Retail Bulk Data Integration" and version "16.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Bulk Data Integration
Search vendor "Oracle" for product "Retail Bulk Data Integration"
19.0.1
Search vendor "Oracle" for product "Retail Bulk Data Integration" and version "19.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Central Office
Search vendor "Oracle" for product "Retail Central Office"
14.0
Search vendor "Oracle" for product "Retail Central Office" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Central Office
Search vendor "Oracle" for product "Retail Central Office"
14.1
Search vendor "Oracle" for product "Retail Central Office" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Eftlink
Search vendor "Oracle" for product "Retail Eftlink"
19.0.1
Search vendor "Oracle" for product "Retail Eftlink" and version "19.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Eftlink
Search vendor "Oracle" for product "Retail Eftlink"
20.0.1
Search vendor "Oracle" for product "Retail Eftlink" and version "20.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Extract Transform And Load
Search vendor "Oracle" for product "Retail Extract Transform And Load"
13.2.8
Search vendor "Oracle" for product "Retail Extract Transform And Load" and version "13.2.8"
-
Affected
Oracle
Search vendor "Oracle"
Retail Financial Integration
Search vendor "Oracle" for product "Retail Financial Integration"
14.1.3.2
Search vendor "Oracle" for product "Retail Financial Integration" and version "14.1.3.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Financial Integration
Search vendor "Oracle" for product "Retail Financial Integration"
15.0.4.0
Search vendor "Oracle" for product "Retail Financial Integration" and version "15.0.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Financial Integration
Search vendor "Oracle" for product "Retail Financial Integration"
16.0.3.0
Search vendor "Oracle" for product "Retail Financial Integration" and version "16.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
14.1.3.2
Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.3.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
15.0.4.0
Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
16.0.3.0
Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
19.0.1.0
Search vendor "Oracle" for product "Retail Integration Bus" and version "19.0.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Invoice Matching
Search vendor "Oracle" for product "Retail Invoice Matching"
16.0.3
Search vendor "Oracle" for product "Retail Invoice Matching" and version "16.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Merchandising System
Search vendor "Oracle" for product "Retail Merchandising System"
19.0.1
Search vendor "Oracle" for product "Retail Merchandising System" and version "19.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Point-of-service
Search vendor "Oracle" for product "Retail Point-of-service"
14.0
Search vendor "Oracle" for product "Retail Point-of-service" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Point-of-service
Search vendor "Oracle" for product "Retail Point-of-service"
14.1
Search vendor "Oracle" for product "Retail Point-of-service" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
14.1.3
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
15.0.3
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Predictive Application Server
Search vendor "Oracle" for product "Retail Predictive Application Server"
16.0.3.0
Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Service Backbone
Search vendor "Oracle" for product "Retail Service Backbone"
14.1.3.2
Search vendor "Oracle" for product "Retail Service Backbone" and version "14.1.3.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Service Backbone
Search vendor "Oracle" for product "Retail Service Backbone"
15.0.4.0
Search vendor "Oracle" for product "Retail Service Backbone" and version "15.0.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Service Backbone
Search vendor "Oracle" for product "Retail Service Backbone"
16.0.3.0
Search vendor "Oracle" for product "Retail Service Backbone" and version "16.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Service Backbone
Search vendor "Oracle" for product "Retail Service Backbone"
19.0.1.0
Search vendor "Oracle" for product "Retail Service Backbone" and version "19.0.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
14.1
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
15.0
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Store Inventory Management
Search vendor "Oracle" for product "Retail Store Inventory Management"
16.0
Search vendor "Oracle" for product "Retail Store Inventory Management" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
16.0.6
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "16.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
17.0.4
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "17.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
18.0.3
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "18.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
19.0.2
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "19.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
20.0.1
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "20.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Timesten In-memory Database
Search vendor "Oracle" for product "Timesten In-memory Database"
< 11.2.2.8.27
Search vendor "Oracle" for product "Timesten In-memory Database" and version " < 11.2.2.8.27"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
>= 4.3.0.1.0 <= 4.3.0.6.0
Search vendor "Oracle" for product "Utilities Framework" and version " >= 4.3.0.1.0 <= 4.3.0.6.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.2.0.2.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.2.0.3.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.4.0.0.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.4.0.2.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.4.0.3.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Testing Accelerator
Search vendor "Oracle" for product "Utilities Testing Accelerator"
6.0.0.1.1
Search vendor "Oracle" for product "Utilities Testing Accelerator" and version "6.0.0.1.1"
-
Affected