Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2021-35515
CVE information
Published
Last Modified
CVSSv2.0 Severity
CVSSv3.1 Severity
Impact Analysis
Description
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 5/10
- Exploit Score
- 10/10
- Access Vector
- Network
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 2.9/10
- Confidentiality Impact
- None
- Availability Impact
- Partial
- Integrity Impact
- None
CVSSv3.1 Score
- Severity
- High
- Base Score
- 7.5/10
- Exploit Score
- 3.9/10
- Access Vector
- Network
- Access Complexity
- Low
- Privileges Required
- None
- Impact Score
- 3.6/10
- Confidentiality Impact
- None
- Availability Impact
- High
- Integrity Impact
- None
- Scope
- Unchanged
- User Interaction
- None
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:apache:commons_compress:*:*:*:*:*:*:*:* |
Yes
|
1.6 | - | |
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_ |
Yes
|
- | - | |
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:* |
Yes
|
- | - | |
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows |
Yes
|
- | - | |
cpe:2.3:a:oracle:flexcube_universal_banking:12.4.0:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3. |
Yes
|
- | - | |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* |
Yes
|
17.7 | - | |
cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:flexcube_universal_banking:*:*:*:*:*:*:*:* |
Yes
|
14.0.0 | - | |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4. |
Yes
|
- | - | |
cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:insurance_policy_administration:11.3.0:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:insurance_policy_administration:11.0.2:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:financial_services_enterprise_case_manageme |
Yes
|
- | - | |
cpe:2.3:a:oracle:financial_services_enterprise_case_manageme |
Yes
|
- | - | |
cpe:2.3:a:oracle:healthcare_data_repository:8.1.0:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_session_route_manager:*:*:*: |
Yes
|
8.0.0 | - | |
cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.2.2:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.3.1:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.1:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_cloud_native_core_unified_da |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_cloud_native_core_service_co |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_cloud_native_core_automated_ |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_billing_and_revenue_manageme |
Yes
|
- | - | |
cpe:2.3:a:oracle:insurance_policy_administration:11.1.0:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:insurance_policy_administration:11.3.1:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.0 |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:* |
Yes
|
18.1 | - | |
cpe:2.3:a:oracle:insurance_policy_administration:11.2.8:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_payments:14.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_trade_finance:14.5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_treasury_management:14.5:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:flexcube_universal_banking:14.5.0:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_diameter_intelligence_hub:*: |
Yes
|
8.0.0 | - | |
cpe:2.3:a:oracle:financial_services_crime_and_compliance_man |
Yes
|
- | - | |
cpe:2.3:a:oracle:financial_services_crime_and_compliance_man |
Yes
|
- | - |
References
- https://commons.apache.org/proper/commons-compress/security-reports.html
- https://lists.apache.org/thread.html/r19ebfd71770ec0617a9ea180e321ef927b3fefb4c81ec5d190
- http://www.openwall.com/lists/oss-security/2021/07/13/1
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://security.netapp.com/advisory/ntap-20211022-0001/
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://lists.apache.org/thread.html/rbaea15ddc5a7c0c6b66660f1d6403b28595e2561bb283eade7
- https://lists.apache.org/thread.html/rb064d705fdfa44b5dae4c366b369ef6597951083196321773b
- https://lists.apache.org/thread.html/rf2f4d7940371a7c7c5b679f50e28fc7fcc82cd00670ced87e0
- https://lists.apache.org/thread.html/rab292091eadd1ecc63c516e9541a7f241091cf2e652b8185a6
- https://lists.apache.org/thread.html/rbe91c512c5385181149ab087b6c909825d34299f5c491c6482
- https://lists.apache.org/thread.html/rd4332baaf6debd03d60deb7ec93bee49e5fdbe958cb6800dff
- https://lists.apache.org/thread.html/rb7adf3e55359819e77230b4586521e5c6874ce5ed93384bdc1
- https://lists.apache.org/thread.html/rfba19167efc785ad3561e7ef29f340d65ac8f0d897aed00e07
- https://lists.apache.org/thread.html/rba65ed5ddb0586f5b12598f55ec7db3633e7b7fede60466367
- https://lists.apache.org/thread.html/r9f54c0caa462267e0cc68b49f141e91432b36b23348d18c65b
- https://lists.apache.org/thread.html/racd0c0381c8404f298b226cd9db2eaae965b14c9c568224aa3
- https://lists.apache.org/thread.html/rb6e1fa80d34e5ada45f72655d84bfd90db0ca44ef19236a491
- https://lists.apache.org/thread.html/r67ef3c07fe3b8c1b02d48012149d280ad6da8e4cec253b5275