CVE-2021-36373
mediumCVSS v3 Base Score
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
2.5%
Exploitation probability in 30 days
Top 16% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
None
Integrity
None
Availability
High
Vulnerability Report
Generated by CyberWatcher
Description
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
CWE
CWE-130Affected Products
apache antoracle agile product lifecycle managementoracle banking trade financeoracle banking treasury managementoracle communications cloud native core automated test suiteoracle communications cloud native core binding support functionoracle communications order and service managementoracle communications unified inventory managementoracle enterprise repositoryoracle financial services analytical applications infrastructure