{"id":"CVE-2021-27568","title":"An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4","summary":"An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may caus…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-754","CWE-200"],"vendor":"json-smart_project","product":"json-smart-v1","affected":["json-smart-v1 < 1.3.2","json-smart-v2 < 2.3.1","json-smart-v2 >= 2.4, < 2.4.1","communications_cloud_native_core_policy = 1.14.0","oss_support_tools < 2.12.42","peoplesoft_enterprise_peopletools = 8.58","peoplesoft_enterprise_peopletools = 8.59","utilities_framework = 4.4.0.0.0","utilities_framework = 4.4.0.2.0","utilities_framework = 4.4.0.3.0","weblogic_server = 12.2.1.3.0","weblogic_server = 12.2.1.4.0","weblogic_server = 14.1.1.0.0"],"patched":["json-smart-v1 1.3.2","json-smart-v2 2.4.1","oss_support_tools 2.12.42"],"published":"2021-02-23","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:08.570","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-27568","references":[{"url":"https://github.com/netplex/json-smart-v1/issues/7","label":"cve@mitre.org"},{"url":"https://github.com/netplex/json-smart-v2/issues/60","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396%40%3Ccommits.druid.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6%40%3Ccommits.druid.apache.org%3E","label":"cve@mitre.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"cve@mitre.org"},{"url":"https://github.com/netplex/json-smart-v1/issues/7","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/netplex/json-smart-v2/issues/60","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-27568.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-27568"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939839"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-27568"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27568"},{"url":"https://access.redhat.com/errata/RHSA-2021:3225"},{"url":"https://access.redhat.com/errata/RHSA-2021:5134"},{"url":"https://access.redhat.com/errata/RHSA-2021:3140"},{"url":"https://access.redhat.com/errata/RHSA-2021:4918"},{"url":"https://access.redhat.com/errata/RHSA-2021:4767"}],"tags":["nvd","exploit-available","csaf","vex","red-hat"],"epss":0.02896,"epssPercentile":0.86522,"exploits":{"github":1,"githubRepos":["https://github.com/arsalanraja987/java-insecure-random-cve-2021-27568"],"checkedAt":"2026-10-08T23:17:21.749Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T23:16:47.315Z","slug":"CVE-2021-27568","body":"## Overview\n\nAn issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.\n\n## Affected\n\n- `json-smart-v1 < 1.3.2`\n- `json-smart-v2 < 2.3.1`\n- `json-smart-v2 >= 2.4, < 2.4.1`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `oss_support_tools < 2.12.42`\n- `peoplesoft_enterprise_peopletools = 8.58`\n- `peoplesoft_enterprise_peopletools = 8.59`\n- `utilities_framework = 4.4.0.0.0`\n- `utilities_framework = 4.4.0.2.0`\n- `utilities_framework = 4.4.0.3.0`\n- `weblogic_server = 12.2.1.3.0`\n- `weblogic_server = 12.2.1.4.0`\n- `weblogic_server = 14.1.1.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `json-smart-v1 1.3.2`\n- `json-smart-v2 2.4.1`\n- `oss_support_tools 2.12.42`\n\n## Vendor advisories\n\n- **RHSA-2021:3225** · Red Hat · fixed in: Red Hat AMQ Streams 1.8.0 · released 2021-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2021:3225)\n- **RHSA-2021:5134** · Red Hat · fixed in: Red Hat Fuse 7.10 · released 2021-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2021:5134)\n- **RHSA-2021:3140** · Red Hat · fixed in: Red Hat Fuse 7.9 · released 2021-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2021:3140)\n- **RHSA-2021:4918** · Red Hat · fixed in: Red Hat Integration · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4918)\n- **RHSA-2021:4767** · Red Hat · fixed in: Red Hat Integration Camel Quarkus 2 · released 2021-11-23 · [advisory](https://access.redhat.com/errata/RHSA-2021:4767)\n- **Red Hat VEX** · Moderate · affected: Red Hat Integration Camel K 1, Red Hat JBoss Fuse 6, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat JBoss Fuse 6, Red Hat OpenShift Container Platform 4, Red Hat Integration Camel K 1 · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-27568.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":32.5,"likelihood":0.6,"exploitation":12,"ransomware":0},"changes":[]}