CVE-2021-36373
Apache Ant TAR archive denial of service vulnerability
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Cuando se lee un archivo TAR especialmente diseñado, se puede hacer que una compilación de Apache Ant asigne grandes cantidades de memoria que finalmente conlleva a un error de falta de memoria, incluso para entradas pequeñas. Esto puede ser usado para interrumpir las compilaciones usando Apache Ant. Apache Ant versiones anteriores a 1.9.16 y 1.10.11 estaban afectados
*Credits:
This issue is similar to https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35517 present in Apache Commons Compress which has been detected by OSS Fuzz.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-07-12 CVE Reserved
- 2021-07-14 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-130: Improper Handling of Length Parameter Inconsistency
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (13)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://ant.apache.org/security.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuoct2021.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Ant Search vendor "Apache" for product "Ant" | >= 1.9.0 < 1.9.16 Search vendor "Apache" for product "Ant" and version " >= 1.9.0 < 1.9.16" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ant Search vendor "Apache" for product "Ant" | >= 1.10.0 < 1.10.11 Search vendor "Apache" for product "Ant" and version " >= 1.10.0 < 1.10.11" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Plm Search vendor "Oracle" for product "Agile Plm" | 9.3.6 Search vendor "Oracle" for product "Agile Plm" and version "9.3.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Banking Trade Finance Search vendor "Oracle" for product "Banking Trade Finance" | 14.5 Search vendor "Oracle" for product "Banking Trade Finance" and version "14.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Banking Treasury Management Search vendor "Oracle" for product "Banking Treasury Management" | 14.5 Search vendor "Oracle" for product "Banking Treasury Management" and version "14.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Automated Test Suite Search vendor "Oracle" for product "Communications Cloud Native Core Automated Test Suite" | 1.9.0 Search vendor "Oracle" for product "Communications Cloud Native Core Automated Test Suite" and version "1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Binding Support Function Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function" | 1.11.0 Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function" and version "1.11.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Order And Service Management Search vendor "Oracle" for product "Communications Order And Service Management" | 7.3 Search vendor "Oracle" for product "Communications Order And Service Management" and version "7.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Order And Service Management Search vendor "Oracle" for product "Communications Order And Service Management" | 7.4 Search vendor "Oracle" for product "Communications Order And Service Management" and version "7.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.4.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.4.1 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.4.2 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.5.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.5.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Repository Search vendor "Oracle" for product "Enterprise Repository" | 11.1.1.7.0 Search vendor "Oracle" for product "Enterprise Repository" and version "11.1.1.7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Analytical Applications Infrastructure Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" | >= 8.0.6 <= 8.1.1 Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.0.6 <= 8.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Insurance Policy Administration Search vendor "Oracle" for product "Insurance Policy Administration" | >= 11.0 <= 11.3.1 Search vendor "Oracle" for product "Insurance Policy Administration" and version " >= 11.0 <= 11.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 17.12.0 <= 17.12.11 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 17.12.0 <= 17.12.11" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 18.8.0 <= 18.8.12 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 18.8.0 <= 18.8.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 19.12.0 <= 19.12.11 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 19.12.0 <= 19.12.11" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Gateway Search vendor "Oracle" for product "Primavera Gateway" | >= 20.12.0 <= 20.12.7 Search vendor "Oracle" for product "Primavera Gateway" and version " >= 20.12.0 <= 20.12.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | >= 17.7 <= 17.12 Search vendor "Oracle" for product "Primavera Unifier" and version " >= 17.7 <= 17.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | 18.8 Search vendor "Oracle" for product "Primavera Unifier" and version "18.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | 19.12 Search vendor "Oracle" for product "Primavera Unifier" and version "19.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | 20.12 Search vendor "Oracle" for product "Primavera Unifier" and version "20.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real-time Decision Server Search vendor "Oracle" for product "Real-time Decision Server" | 3.2.0.0 Search vendor "Oracle" for product "Real-time Decision Server" and version "3.2.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Real-time Decision Server Search vendor "Oracle" for product "Real-time Decision Server" | 11.1.1.9.0 Search vendor "Oracle" for product "Real-time Decision Server" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Advanced Inventory Planning Search vendor "Oracle" for product "Retail Advanced Inventory Planning" | 14.1 Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Advanced Inventory Planning Search vendor "Oracle" for product "Retail Advanced Inventory Planning" | 15.0 Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Advanced Inventory Planning Search vendor "Oracle" for product "Retail Advanced Inventory Planning" | 16.0 Search vendor "Oracle" for product "Retail Advanced Inventory Planning" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Back Office Search vendor "Oracle" for product "Retail Back Office" | 14.0 Search vendor "Oracle" for product "Retail Back Office" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Back Office Search vendor "Oracle" for product "Retail Back Office" | 14.1 Search vendor "Oracle" for product "Retail Back Office" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Bulk Data Integration Search vendor "Oracle" for product "Retail Bulk Data Integration" | 16.0.3.0 Search vendor "Oracle" for product "Retail Bulk Data Integration" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Bulk Data Integration Search vendor "Oracle" for product "Retail Bulk Data Integration" | 19.0.1 Search vendor "Oracle" for product "Retail Bulk Data Integration" and version "19.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Central Office Search vendor "Oracle" for product "Retail Central Office" | 14.0 Search vendor "Oracle" for product "Retail Central Office" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Central Office Search vendor "Oracle" for product "Retail Central Office" | 14.1 Search vendor "Oracle" for product "Retail Central Office" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Eftlink Search vendor "Oracle" for product "Retail Eftlink" | 19.0.1 Search vendor "Oracle" for product "Retail Eftlink" and version "19.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Eftlink Search vendor "Oracle" for product "Retail Eftlink" | 20.0.1 Search vendor "Oracle" for product "Retail Eftlink" and version "20.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Extract Transform And Load Search vendor "Oracle" for product "Retail Extract Transform And Load" | 13.2.8 Search vendor "Oracle" for product "Retail Extract Transform And Load" and version "13.2.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 14.1.3.2 Search vendor "Oracle" for product "Retail Financial Integration" and version "14.1.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 15.0.4.0 Search vendor "Oracle" for product "Retail Financial Integration" and version "15.0.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 16.0.3.0 Search vendor "Oracle" for product "Retail Financial Integration" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.1.3.2 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 15.0.4.0 Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 16.0.3.0 Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 19.0.1.0 Search vendor "Oracle" for product "Retail Integration Bus" and version "19.0.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Invoice Matching Search vendor "Oracle" for product "Retail Invoice Matching" | 16.0.3 Search vendor "Oracle" for product "Retail Invoice Matching" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Merchandising System Search vendor "Oracle" for product "Retail Merchandising System" | 19.0.1 Search vendor "Oracle" for product "Retail Merchandising System" and version "19.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Point-of-service Search vendor "Oracle" for product "Retail Point-of-service" | 14.0 Search vendor "Oracle" for product "Retail Point-of-service" and version "14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Point-of-service Search vendor "Oracle" for product "Retail Point-of-service" | 14.1 Search vendor "Oracle" for product "Retail Point-of-service" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 14.1.3 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "14.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 15.0.3 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "15.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Predictive Application Server Search vendor "Oracle" for product "Retail Predictive Application Server" | 16.0.3.0 Search vendor "Oracle" for product "Retail Predictive Application Server" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 14.1.3.2 Search vendor "Oracle" for product "Retail Service Backbone" and version "14.1.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 15.0.4.0 Search vendor "Oracle" for product "Retail Service Backbone" and version "15.0.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 16.0.3.0 Search vendor "Oracle" for product "Retail Service Backbone" and version "16.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 19.0.1.0 Search vendor "Oracle" for product "Retail Service Backbone" and version "19.0.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 14.1 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 15.0 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 16.0 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "16.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 16.0.6 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "16.0.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 17.0.4 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "17.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 18.0.3 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "18.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 19.0.2 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "19.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 20.0.1 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "20.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Timesten In-memory Database Search vendor "Oracle" for product "Timesten In-memory Database" | < 11.2.2.8.27 Search vendor "Oracle" for product "Timesten In-memory Database" and version " < 11.2.2.8.27" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | >= 4.3.0.1.0 <= 4.3.0.6.0 Search vendor "Oracle" for product "Utilities Framework" and version " >= 4.3.0.1.0 <= 4.3.0.6.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.2.0.2.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.2.0.3.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.4.0.0.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.4.0.2.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.4.0.3.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Testing Accelerator Search vendor "Oracle" for product "Utilities Testing Accelerator" | 6.0.0.1.1 Search vendor "Oracle" for product "Utilities Testing Accelerator" and version "6.0.0.1.1" | - |
Affected
|