CVE-2021-35517High· 7.5▾ TwilightWhen reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack agains…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 2.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
11%
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
commons_compress >= 1.1, <= 1.20active_iq_unified_manageroncommand_insightbanking_apis >= 18.1, <= 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_digital_experience >= 18.1, <= 18.3banking_digital_experience = 19.1banking_digital_experience = 19.2banking_digital_experience = 20.1banking_digital_experience = 21.1banking_enterprise_default_management = 2.7.0banking_party_management = 2.7.0banking_payments = 14.5banking_trade_finance = 14.5banking_treasury_management = 14.5business_process_management_suite = 12.2.1.3.0business_process_management_suite = 12.2.1.4.0commerce_guided_search = 11.3.2communications_billing_and_revenue_management = 12.0.0.4communications_cloud_native_core_service_communication_proxy = 1.14.0communications_cloud_native_core_unified_data_repository = 1.14.0communications_diameter_intelligence_hub >= 8.0.0, <= 8.2.3communications_session_route_manager >= 8.0.0, <= 8.2.5financial_services_crime_and_compliance_management_studio = 8.0.8.2.0financial_services_crime_and_compliance_management_studio = 8.0.8.3.0financial_services_enterprise_case_management = 8.0.7.2.0financial_services_enterprise_case_management = 8.0.8.1.0flexcube_universal_banking >= 14.0.0, <= 14.3.0flexcube_universal_banking = 12.4flexcube_universal_banking = 14.5healthcare_data_repository = 8.1.0insurance_policy_administration = 11.0.2insurance_policy_administration = 11.1.0insurance_policy_administration = 11.2.8insurance_policy_administration = 11.3.0insurance_policy_administration = 11.3.1peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59primavera_unifier >= 17.7, <= 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12utilities_testing_accelerator = 6.0.0.1.1utilities_testing_accelerator = 6.0.0.2.2utilities_testing_accelerator = 6.0.0.3.1webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0communications_messaging_server = 8.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-36090High· 7.5When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs
CVE-2021-36374Medium· 5.5When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs
CVE-2021-36373Medium· 5.5When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs
CVE-2022-22971Medium· 6.5In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVE-2022-22970Medium· 5.3In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field…
CVE-2022-36124High· 7.5It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system