CVE-2021-36374

medium Apache
CVSS v3 Base Score
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
2.6%
Exploitation probability in 30 days
Top 15% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
None
Integrity
None
Availability
High
Published: July 14, 2021 (1882 days ago)
Last Modified: August 25, 2026
Vendor: Apache
Source: NVD

Description

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

CWE

CWE-130

Affected Products

apache antoracle agile engineering data managementoracle agile product lifecycle managementoracle banking trade financeoracle banking treasury managementoracle communications cloud native core automated test suiteoracle communications cloud native core binding support functionoracle communications diameter intelligence huboracle communications order and service managementoracle communications unified inventory management

References