Vulnerability Name: | CVE-2019-10093 (CCN-164710) | ||||||||||||||||||||||||||||||||
Assigned: | 2019-08-02 | ||||||||||||||||||||||||||||||||
Published: | 2019-08-02 | ||||||||||||||||||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||||||||||||||||||
Summary: | In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-770 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-10093 Source: XF Type: UNKNOWN apache-cve201910093-dos(164710) Source: MLIST Type: UNKNOWN [tika-dev] 20190813 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: CONFIRM Type: Mailing List, Vendor Advisory https://lists.apache.org/thread.html/a5a44eff1b9eda3bc69d22943a1030c43d376380c75d3ab04d0c1a21@%3Cdev.tika.apache.org%3E Source: MLIST Type: UNKNOWN [tika-dev] 20190812 Re: security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: MLIST Type: Mailing List, Patch, Vendor Advisory [tika-dev] 20190809 security fixes for CVE-2019-10088 and CVE-2019-1009{3,4} Source: MLIST Type: UNKNOWN [lucene-solr-user] 20200320 CVEs (vulnerabilities) that apply to Solr 8.4.1 Source: CCN Type: oss-sec Mailing List, Fri, 2 Aug 2019 07:34:26 -0400 [CVE-2019-10093] Denial of Service in Apache Tika's 2003ml and 2006ml Parsers Source: CONFIRM Type: UNKNOWN https://security.netapp.com/advisory/ntap-20190828-0004/ Source: CCN Type: Apache Tika Web site Apache Tika Source: CCN Type: IBM Security Bulletin 6495351 (Log Analysis) Apache Solr, shipped with IBM Operations Analytics - Log Analysis, susceptible to multiple vulnerabilities in Apache Tika Source: CCN Type: IBM Security Bulletin 6524700 (Planning Analytics Workspace) IBM Planning Analytics Workspace is affected by security vulnerabilities Source: N/A Type: UNKNOWN N/A Source: MISC Type: UNKNOWN https://www.oracle.com/security-alerts/cpujan2020.html | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |