HIGH · 7.5

CVE-2021-36090

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mo...

Vulnerability Description

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheCommons Compress>= 1.0, < 1.21
OracleBanking Apis>= 18.1, <= 18.3
OracleBanking Digital Experience>= 18.1, <= 18.3
OracleBanking Enterprise Default Management2.7.0
OracleBanking Party Management2.7.0
OracleBanking Payments14.5
OracleBanking Platform2.6.2
OracleBanking Trade Finance14.5
OracleBanking Treasury Management14.5
OracleBusiness Process Management Suite12.2.1.3.0
OracleCommerce Guided Search11.3.2
OracleCommunications Billing And Revenue Management12.0.0.4
OracleCommunications Cloud Native Core Automated Test Suite1.8.0
OracleCommunications Cloud Native Core Service Communication Proxy1.14.0
OracleCommunications Cloud Native Core Unified Data Repository1.14.0
OracleCommunications Diameter Intelligence Hub>= 8.0.0, <= 8.2.3
OracleCommunications Element Manager>= 8.2.0, <= 8.2.4.0
OracleCommunications Session Report Manager>= 8.2.0, <= 8.2.5.0
OracleCommunications Session Route Manager>= 8.0.0, <= 8.2.5.0
OracleCommunications Unified Inventory Management7.4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-36090?

CVE-2021-36090 is a vulnerability with a CVSS score of 7.5 (HIGH). When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mo...

How severe is CVE-2021-36090?

CVE-2021-36090 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-36090?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Commons Compress, Oracle Banking Apis, Oracle Banking Digital Experience, Oracle Banking Enterprise Default Management, Oracle Banking Party Management.