---
id: CVE-2021-27568
title: >-
  An issue was discovered in netplex json-smart-v1 through 2015-10-23 and
  json-smart-v2 through 2.4
summary: >-
  An issue was discovered in netplex json-smart-v1 through 2015-10-23 and
  json-smart-v2 through 2.4. An exception is thrown from a function, but it is
  not caught, as demonstrated by NumberFormatException. When it is not caught,
  it may caus…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-754
  - CWE-200
vendor: json-smart_project
product: json-smart-v1
affected:
  - json-smart-v1 < 1.3.2
  - json-smart-v2 < 2.3.1
  - 'json-smart-v2 >= 2.4, < 2.4.1'
  - communications_cloud_native_core_policy = 1.14.0
  - oss_support_tools < 2.12.42
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - utilities_framework = 4.4.0.0.0
  - utilities_framework = 4.4.0.2.0
  - utilities_framework = 4.4.0.3.0
  - weblogic_server = 12.2.1.3.0
  - weblogic_server = 12.2.1.4.0
  - weblogic_server = 14.1.1.0.0
patched:
  - json-smart-v1 1.3.2
  - json-smart-v2 2.4.1
  - oss_support_tools 2.12.42
published: '2021-02-23'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:08.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-27568'
references:
  - url: 'https://github.com/netplex/json-smart-v1/issues/7'
    label: cve@mitre.org
  - url: 'https://github.com/netplex/json-smart-v2/issues/60'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396%40%3Ccommits.druid.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6%40%3Ccommits.druid.apache.org%3E
    label: cve@mitre.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: cve@mitre.org
  - url: 'https://github.com/netplex/json-smart-v1/issues/7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/netplex/json-smart-v2/issues/60'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb6287f5aa628c8d9af52b5401ec6cc51b6fc28ab20d318943453e396%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/re237267da268c690df5e1c6ea6a38a7fc11617725e8049490f58a6fa%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf70210b4d63191c0bfb2a0d5745e104484e71703bf5ad9cb01c980c6%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-27568.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-27568'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1939839'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-27568'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-27568'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3225'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5134'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3140'
  - url: 'https://access.redhat.com/errata/RHSA-2021:4918'
  - url: 'https://access.redhat.com/errata/RHSA-2021:4767'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.02896
epssPercentile: 0.86522
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/arsalanraja987/java-insecure-random-cve-2021-27568'
  checkedAt: '2026-10-08T23:17:21.749Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.315Z'
---

## Overview

An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

## Affected

- `json-smart-v1 < 1.3.2`
- `json-smart-v2 < 2.3.1`
- `json-smart-v2 >= 2.4, < 2.4.1`
- `communications_cloud_native_core_policy = 1.14.0`
- `oss_support_tools < 2.12.42`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `utilities_framework = 4.4.0.0.0`
- `utilities_framework = 4.4.0.2.0`
- `utilities_framework = 4.4.0.3.0`
- `weblogic_server = 12.2.1.3.0`
- `weblogic_server = 12.2.1.4.0`
- `weblogic_server = 14.1.1.0.0`

## Remediation

Upgrade past the affected range:

- `json-smart-v1 1.3.2`
- `json-smart-v2 2.4.1`
- `oss_support_tools 2.12.42`

## Vendor advisories

- **RHSA-2021:3225** · Red Hat · fixed in: Red Hat AMQ Streams 1.8.0 · released 2021-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2021:3225)
- **RHSA-2021:5134** · Red Hat · fixed in: Red Hat Fuse 7.10 · released 2021-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2021:5134)
- **RHSA-2021:3140** · Red Hat · fixed in: Red Hat Fuse 7.9 · released 2021-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2021:3140)
- **RHSA-2021:4918** · Red Hat · fixed in: Red Hat Integration · released 2021-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2021:4918)
- **RHSA-2021:4767** · Red Hat · fixed in: Red Hat Integration Camel Quarkus 2 · released 2021-11-23 · [advisory](https://access.redhat.com/errata/RHSA-2021:4767)
- **Red Hat VEX** · Moderate · affected: Red Hat Integration Camel K 1, Red Hat JBoss Fuse 6, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat JBoss Fuse 6, Red Hat OpenShift Container Platform 4, Red Hat Integration Camel K 1 · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-27568.json)
