MEDIUM · 6.5

CVE-2021-41973

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer an...

Vulnerability Description

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheMina< 2.0.22
OracleBanking Payments14.5
OracleBanking Trade Finance Process Management14.5
OracleBanking Treasury Management14.5
OracleCommunications Cloud Native Core Console1.9.0
OracleCustomer Management And Segmentation Foundation18.0
OracleFlexcube Universal Banking>= 14.0, <= 14.3
OracleFusion Middleware Common Libraries And Tools12.2.1.3.0
OracleOss Support Tools2.12.42

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-41973?

CVE-2021-41973 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer an...

How severe is CVE-2021-41973?

CVE-2021-41973 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-41973?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Mina, Oracle Banking Payments, Oracle Banking Trade Finance Process Management, Oracle Banking Treasury Management, Oracle Communications Cloud Native Core Console.