HIGH · 7.5

CVE-2021-35517

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mo...

Vulnerability Description

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheCommons Compress>= 1.1, <= 1.20
NetappActive Iq Unified Manager-
NetappOncommand Insight-
OracleBanking Apis>= 18.1, <= 18.3
OracleBanking Digital Experience>= 18.1, <= 18.3
OracleBanking Enterprise Default Management2.7.0
OracleBanking Party Management2.7.0
OracleBanking Payments14.5
OracleBanking Trade Finance14.5
OracleBanking Treasury Management14.5
OracleBusiness Process Management Suite12.2.1.3.0
OracleCommerce Guided Search11.3.2
OracleCommunications Billing And Revenue Management12.0.0.4
OracleCommunications Cloud Native Core Service Communication Proxy1.14.0
OracleCommunications Cloud Native Core Unified Data Repository1.14.0
OracleCommunications Diameter Intelligence Hub>= 8.0.0, <= 8.2.3
OracleCommunications Session Route Manager>= 8.0.0, <= 8.2.5
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleFinancial Services Enterprise Case Management8.0.7.2.0
OracleFlexcube Universal Banking>= 14.0.0, <= 14.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-35517?

CVE-2021-35517 is a vulnerability with a CVSS score of 7.5 (HIGH). When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mo...

How severe is CVE-2021-35517?

CVE-2021-35517 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-35517?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Commons Compress, Netapp Active Iq Unified Manager, Netapp Oncommand Insight, Oracle Banking Apis, Oracle Banking Digital Experience.