MEDIUM · 4.8

CVE-2021-29425

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly provi...

Vulnerability Description

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ApacheCommons Io2.2
DebianDebian Linux9.0
OracleAccess Manager11.1.2.3.0
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.6
OracleApplication Performance Management13.4.1.0
OracleApplication Testing Suite13.3.0.1
OracleBanking Apis18.1
OracleBanking Digital Experience17.2
OracleBanking Enterprise Default Management2.6.2
OracleBanking Enterprise Default Managment>= 2.3.0, <= 2.4.0
OracleBanking Party Management2.7.0
OracleBanking Platform>= 2.3.0, <= 2.4.1
OracleBlockchain Platform< 21.1.2
OracleCommerce Guided Search11.3.2
OracleCommunications Application Session Controller3.9.0
OracleCommunications Billing And Revenue Management Elastic Charging Engine11.3
OracleCommunications Cloud Native Core Network Repository Function1.14.0
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Cloud Native Core Unified Data Repository1.4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-29425?

CVE-2021-29425 is a vulnerability with a CVSS score of 4.8 (MEDIUM). In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly provi...

How severe is CVE-2021-29425?

CVE-2021-29425 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-29425?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Commons Io, Debian Debian Linux, Oracle Access Manager, Oracle Agile Engineering Data Management, Oracle Agile Plm.