Vulnerability Name: CVE-2020-1945 (CCN-181875) Assigned: 2019-12-02 Published: 2020-05-13 Updated: 2022-04-04 Summary: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process. CVSS v3 Severity: 6.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N )5.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): HighPrivileges Required (PR): LowUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): None
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N )5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): None
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-668 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2020-1945 Source: SUSE Type: Mailing List, Third Party AdvisoryopenSUSE-SU-2020:1022 Source: MLIST Type: Mailing List, Third Party Advisory[oss-security] 20200930 [CVE-2020-11979] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Third Party Advisory[oss-security] 20201206 [CVE-2020-17521]: Apache Groovy Information Disclosure Source: CCN Type: Apache Ant Web siteApache Ant Source: XF Type: UNKNOWNapache-cve20201945-sec-bypass(181875) Source: MLIST Type: Mailing List, Vendor Advisory[hive-issues] 20200530 [jira] [Assigned] (HIVE-23583) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20201006 [jira] [Updated] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 Source: MLIST Type: Mailing List, Mitigation, Patch, Vendor Advisory[creadur-dev] 20200518 [jira] [Assigned] (RAT-269) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20200930 [jira] [Created] (RAT-274) Update to latest Ant in order to fix CVE-2020-11979 Source: MLIST Type: Mailing List, Vendor Advisory[hive-dev] 20200530 [jira] [Created] (HIVE-23583) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20201006 [jira] [Commented] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20201006 [jira] [Updated] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 / raise compiler level to JDK8 Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20200703 [jira] [Commented] (RAT-269) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[hive-issues] 20201022 [jira] [Commented] (HIVE-23583) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[hive-issues] 20200530 [jira] [Updated] (HIVE-23583) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20201006 [jira] [Assigned] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 Source: MLIST Type: Mailing List, Patch, Vendor Advisory[myfaces-commits] 20200826 [myfaces-tobago] branch tobago-2.x updated: update ant because of CVE-2020-1945 Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20201006 [jira] [Resolved] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 / raise compiler level to JDK8 Source: MLIST Type: Mailing List, Vendor Advisory[groovy-notifications] 20201126 [jira] [Updated] (GROOVY-9552) Bump Ant versions to address: [CVE-2020-1945] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Patch, Vendor Advisory[groovy-commits] 20201126 [groovy] branch GROOVY_2_4_X updated: GROOVY-9552: Bump Ant versions to address: [CVE-2020-1945] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Patch, Vendor Advisory[db-torque-dev] 20200715 svn commit: r1879896 - in /db/torque/torque4/trunk: ./ torque-ant-tasks/ torque-ant-tasks/src/test/java/org/apache/torque/ant/task/ torque-generator/src/main/java/org/apache/torque/generator/control/ torque-generator/src/main/java/org/apache/torque/gen... Source: MLIST Type: Mailing List, Vendor Advisory[hive-issues] 20200530 [jira] [Commented] (HIVE-23583) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[hive-issues] 20200804 [jira] [Commented] (HIVE-23583) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[hive-issues] 20200621 [jira] [Commented] (HIVE-23583) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MISC Type: Mailing List, Vendor Advisoryhttps://lists.apache.org/thread.html/r8e592bbfc016a5dbe2a8c0e81ff99682b9c78c453621b82c14e7b75e%40%3Cdev.ant.apache.org%3E Source: MLIST Type: Mailing List, Mitigation, Patch, Vendor Advisory[creadur-dev] 20200518 [jira] [Closed] (RAT-269) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[announce] 20201205 [SECURITY] CVE-2020-17521: Apache Groovy Information Disclosure Source: MLIST Type: Mailing List, Vendor Advisory[groovy-dev] 20201205 [SECURITY] CVE-2020-17521: Apache Groovy Information Disclosure Source: MLIST Type: Mailing List, Vendor Advisory[groovy-users] 20201205 [SECURITY] CVE-2020-17521: Apache Groovy Information Disclosure Source: MLIST Type: Mailing List, Vendor Advisory[groovy-notifications] 20201207 [jira] [Closed] (GROOVY-9824) CVE-2020-17521 Apache Groovy Information Disclosure Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20210419 [jira] [Commented] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 / raise compiler level to JDK8 Source: MLIST Type: Mailing List, Patch, Vendor Advisory[myfaces-commits] 20201211 [myfaces-tobago] 02/22: update ant because of CVE-2020-1945 Source: MLIST Type: Mailing List, Vendor Advisory[announce] 20200930 [CVE-2020-11979] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20210621 [jira] [Commented] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 / raise compiler level to JDK8 Source: MLIST Type: Mailing List, Vendor Advisory[ant-dev] 20200930 [CVE-2020-11979] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Vendor Advisory[ant-user] 20200930 [CVE-2020-11979] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Vendor Advisory[groovy-notifications] 20201126 [jira] [Comment Edited] (GROOVY-9552) Bump Ant versions to address: [CVE-2020-1945] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Mitigation, Patch, Vendor Advisory[creadur-dev] 20200518 [jira] [Commented] (RAT-269) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mitigation, Vendor Advisory[creadur-dev] 20200518 [jira] [Created] (RAT-269) Fix CVE-2020-1945: Apache Ant insecure temporary file vulnerability by updating to latest ANT Source: MLIST Type: Mailing List, Vendor Advisory[groovy-notifications] 20200522 [jira] [Closed] (GROOVY-9552) Bump Ant versions to address: [CVE-2020-1945] Apache Ant insecure temporary file vulnerability Source: MLIST Type: Mailing List, Patch, Vendor Advisory[creadur-commits] 20200518 [creadur-rat] branch master updated: RAT-269: Update Apache ANT to fix CVE-2020-1945 Source: MLIST Type: Mailing List, Vendor Advisory[creadur-dev] 20200930 [jira] [Updated] (RAT-274) Update to at least Ant 1.10.8/1.9.15 in order to fix CVE-2020-11979 Source: MLIST Type: Patch, Vendor Advisory[creadur-commits] 20200518 [creadur-rat] 03/03: RAT-269: Update Apache ANT to fix CVE-2020-1945 Source: FEDORA Type: Mailing List, Vendor AdvisoryFEDORA-2020-7f07da3fef Source: FEDORA Type: Mailing List, Vendor AdvisoryFEDORA-2020-52741b0a49 Source: CCN Type: oss-sec Mailing List, Wed, 13 May 2020 18:38:16 +0200[CVE-2020-1945] Apache Ant insecure temporary file vulnerability Source: GENTOO Type: Third Party AdvisoryGLSA-202007-34 Source: UBUNTU Type: Mailing List, Vendor AdvisoryUSN-4380-1 Source: CCN Type: IBM Security Bulletin 6327149 (Spectrum Symphony)Vulnerability in Apache Ant affects IBM Platform Symphony and IBM Spectrum Symphony Source: CCN Type: IBM Security Bulletin 6344075 (QRadar SIEM)IBM QRadar SIEM is vulnerable to Using Components with Known Vulnerabilities Source: CCN Type: IBM Security Bulletin 6445355 (Log Analysis)Vulnerability in Apache Ant affect IBM Operations Analytics - Log Analysis Analysis (CVE-2020-1945) Source: CCN Type: IBM Security Bulletin 6453467 (Control Center)Apache Ant Vulnerabilities Affect IBM Control Center (CVE-2020-1945, CVE-2020-11979) Source: CCN Type: IBM Security Bulletin 6520510 (Cognos Analytics)IBM Cognos Analytics has addressed multiple vulnerabilities Source: CCN Type: IBM Security Bulletin 6967183 (Cloud Pak System Software Suite)Multiple vulnerabilities in Open Source software used by Cloud Pak System Source: CCN Type: IBM Security Bulletin 6967553 (Cloud Pak for Data System)Vulnerability in ant-1.8.1.jar affects IBM Cloud Pak for Data System 2.0 (CPDS 2.0) Source: CCN Type: IBM Security Bulletin 6969771 (Log Analysis)Multiple vulnerabilities affect Apache Ant shipped with IBM Operations Analytics - Log Analysis Source: CCN Type: IBM Security Bulletin 6987499 (Business Automation Workflow traditional)Multiple vulnerabilities in DITA may affect IBM Business Automation Workflow and IBM Case Manager Source: N/A Type: Patch, Third Party AdvisoryN/A Source: CCN Type: Oracle Critical Patch Update Advisory - April 2021Oracle Critical Patch Update Advisory - April 2021 Source: MISC Type: Patch, Third Party Advisoryhttps://www.oracle.com/security-alerts/cpuApr2021.html Source: CCN Type: Oracle CPUJan2021Oracle Critical Patch Update Advisory - January 2021 Source: MISC Type: Patch, Third Party Advisoryhttps://www.oracle.com/security-alerts/cpujan2021.html Source: MISC Type: Patch, Third Party Advisoryhttps://www.oracle.com/security-alerts/cpujan2022.html Source: CCN Type: Oracle CPUJul2020Oracle Critical Patch Update Advisory - July 2020 Source: MISC Type: Patch, Third Party Advisoryhttps://www.oracle.com/security-alerts/cpujul2020.html Source: CCN Type: Oracle CPUJul2021Oracle Critical Patch Update Advisory - July 2021 Source: CCN Type: Oracle CPUOct2020Oracle Critical Patch Update Advisory - October 2020 Source: MISC Type: Patch, Third Party Advisoryhttps://www.oracle.com/security-alerts/cpuoct2020.html Source: CCN Type: Oracle CPUOct2021Oracle Critical Patch Update Advisory - October 2021 Source: MISC Type: Patch, Third Party Advisoryhttps://www.oracle.com/security-alerts/cpuoct2021.html Vulnerable Configuration: Configuration 1 :cpe:/a:apache:ant:*:*:*:*:*:*:*:* (Version >= 1.1 and <= 1.9.14)OR cpe:/a:apache:ant:*:*:*:*:*:*:*:* (Version >= 1.10.0 and <= 1.10.7) Configuration 2 :cpe:/o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* Configuration 3 :cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:* OR cpe:/o:fedoraproject:fedora:32:*:*:*:*:*:*:* Configuration 4 :cpe:/o:opensuse:leap:15.2:*:*:*:*:*:*:* Configuration 5 :cpe:/a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:banking_enterprise_collections:*:*:*:*:*:*:*:* (Version >= 2.7.0 and <= 2.9.0) OR cpe:/a:oracle:banking_liquidity_management:*:*:*:*:*:*:*:* (Version >= 14.0.0 and <= 14.4.0) OR cpe:/a:oracle:banking_platform:*:*:*:*:*:*:*:* (Version >= 2.4.0 and <= 2.9.0) OR cpe:/a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:category_management_planning_&_optimization:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_asap:7.3:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:* (Version >= 8.0.0 and <= 8.2.2) OR cpe:/a:oracle:communications_metasolv_solution:6.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_order_and_service_management:7.3:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_order_and_service_management:7.4:*:*:*:*:*:*:* OR cpe:/a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:* OR cpe:/a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* (Version >= 8.0.6 and <= 8.1.0) OR cpe:/a:oracle:flexcube_investor_servicing:12.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:12.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:12.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:14.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:14.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:health_sciences_information_manager:*:*:*:*:*:*:*:* (Version >= 3.0 and <= 3.0.2) OR cpe:/a:oracle:primavera_gateway:*:*:*:*:*:*:*:* (Version >= 16.2.0 and <= 16.2.11) OR cpe:/a:oracle:primavera_gateway:*:*:*:*:*:*:*:* (Version >= 17.12.0 and <= 17.12.7) OR cpe:/a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* OR cpe:/a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:* OR cpe:/a:oracle:primavera_unifier:*:*:*:*:*:*:*:* (Version >= 17.7 and <= 17.12) OR cpe:/a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* OR cpe:/a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* OR cpe:/a:oracle:rapid_planning:12.1:*:*:*:*:*:*:* OR cpe:/a:oracle:rapid_planning:12.2:*:*:*:*:*:*:* OR cpe:/a:oracle:real-time_decision_server:3.2.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_advanced_inventory_planning:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_advanced_inventory_planning:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_assortment_planning:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_assortment_planning:16.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_back_office:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_bulk_data_integration:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_bulk_data_integration:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_bulk_data_integration:19.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_central_office:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_central_office:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_data_extractor_for_merchandising:1.9:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_data_extractor_for_merchandising:1.10:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_extract_transform_and_load:13.2.5:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_extract_transform_and_load:13.2.8:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_financial_integration:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_financial_integration:15.0.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_financial_integration:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_financial_integration:16.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:15.0.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:16.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:19.0.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_item_planning:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_macro_space_optimization:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_merchandise_financial_planning:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_point-of-service:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_point-of-service:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_point-of-service:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:14.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:14.1.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:16.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_regular_price_optimization:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_regular_price_optimization:16.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_replenishment_optimization:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:14.1.3.2:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:15.0.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:16.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:19.0.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_size_profile_optimization:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_size_profile_optimization:16.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:14.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:14.1.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:16.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:15.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:* (Version < 11.2.2.8.27) OR cpe:/a:oracle:timesten_in-memory_database:11.2.2.8.49:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:2.2.0.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:4.2.0.2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:4.2.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:*:*:*:*:*:*:*:* (Version >= 4.3.0.1.0 and <= 4.3.0.6.0) OR cpe:/a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:apache:ant:1.1:*:*:*:*:*:*:* OR cpe:/a:apache:ant:1.9.14:*:*:*:*:*:*:* OR cpe:/a:apache:ant:1.10.0:-:*:*:*:*:*:* OR cpe:/a:apache:ant:1.10.7:-:*:*:*:*:*:* AND cpe:/a:oracle:retail_point-of-service:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:12.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:12.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* OR cpe:/a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_private_banking:12.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_private_banking:12.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:14.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_store_inventory_management:14.1.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_back_office:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:14.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:14.1.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:2.2.0.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:4.2.0.2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:4.2.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:utilities_framework:4.3.0.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_asap:7.3:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_assortment_planning:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:communications_metasolv_solution:6.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:12.4.0:*:*:*:*:*:*:* OR cpe:/a:ibm:spectrum_symphony:7.2.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:spectrum_symphony:7.1.2:*:*:*:*:*:*:* OR cpe:/a:oracle:primavera_unifier:17.12:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_financial_integration:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_financial_integration:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_bulk_data_integration:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_central_office:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_central_office:14.1:*:*:*:*:*:*:* OR cpe:/a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:* OR cpe:/a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:platform_symphony:7.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:spectrum_symphony:7.2.1:*:*:*:*:*:*:* OR cpe:/a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:14.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:flexcube_investor_servicing:14.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:spectrum_symphony:7.3:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.1:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.2:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.3:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.4:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.5:*:*:*:*:*:*:* OR cpe:/a:ibm:log_analysis:1.3.6:*:*:*:*:*:*:* OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.3.3:p4:*:*:*:*:*:* OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4.0:-:*:*:*:*:*:* OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4.1:-:*:*:*:*:*:* OR cpe:/a:ibm:control_center:6.2.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:cognos_analytics:11.2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:cognos_analytics:11.1.7:-:*:*:*:*:*:* OR cpe:/a:ibm:business_automation_workflow:20.0.0.1:*:*:*:traditional:*:*:* OR cpe:/a:ibm:business_automation_workflow:20.0.0.2:*:*:*:traditional:*:*:* OR cpe:/a:ibm:business_automation_workflow:21.0.1:*:*:*:traditional:*:*:* OR cpe:/a:ibm:case_manager:5.3.3:*:*:*:*:*:*:* OR cpe:/a:ibm:business_automation_workflow:22.0.1:*:*:*:traditional:*:*:* OR cpe:/a:ibm:business_automation_workflow:21.0.3.1:*:*:*:traditional:*:*:* OR cpe:/a:ibm:business_automation_workflow:22.0.2:*:*:*:traditional:*:*:* Denotes that component is vulnerable Oval Definitions BACK
apache ant *
apache ant *
canonical ubuntu linux 19.10
fedoraproject fedora 31
fedoraproject fedora 32
opensuse leap 15.2
oracle agile engineering data management 6.2.1.0
oracle banking enterprise collections *
oracle banking liquidity management *
oracle banking platform *
oracle business process management suite 12.2.1.3.0
oracle business process management suite 12.2.1.4.0
oracle category management planning & optimization 15.0.3
oracle communications asap 7.3
oracle communications diameter signaling router *
oracle communications metasolv solution 6.3.0
oracle communications order and service management 7.3
oracle communications order and service management 7.4
oracle data integrator 12.2.1.3.0
oracle data integrator 12.2.1.4.0
oracle endeca information discovery studio 3.2.0
oracle enterprise manager ops center 12.4.0.0
oracle enterprise repository 11.1.1.7.0
oracle financial services analytical applications infrastructure *
oracle flexcube investor servicing 12.1.0
oracle flexcube investor servicing 12.3.0
oracle flexcube investor servicing 12.4.0
oracle flexcube investor servicing 14.0.0
oracle flexcube investor servicing 14.1.0
oracle flexcube private banking 12.0.0
oracle flexcube private banking 12.1.0
oracle health sciences information manager *
oracle primavera gateway *
oracle primavera gateway *
oracle primavera unifier 16.1
oracle primavera unifier 16.2
oracle primavera unifier *
oracle primavera unifier 18.8
oracle primavera unifier 19.12
oracle rapid planning 12.1
oracle rapid planning 12.2
oracle real-time decision server 3.2.1.0
oracle retail advanced inventory planning 14.1
oracle retail advanced inventory planning 15.0
oracle retail advanced inventory planning 16.0
oracle retail assortment planning 15.0.3
oracle retail assortment planning 16.0.3
oracle retail back office 14.0
oracle retail back office 14.1
oracle retail bulk data integration 15.0
oracle retail bulk data integration 16.0
oracle retail bulk data integration 16.0.3.0
oracle retail bulk data integration 19.0.1
oracle retail central office 14.0
oracle retail central office 14.1
oracle retail data extractor for merchandising 1.9
oracle retail data extractor for merchandising 1.10
oracle retail extract transform and load 13.2.5
oracle retail extract transform and load 13.2.8
oracle retail financial integration 14.1.3.2
oracle retail financial integration 15.0
oracle retail financial integration 15.0.4.0
oracle retail financial integration 16.0
oracle retail financial integration 16.0.3.0
oracle retail integration bus 14.1
oracle retail integration bus 14.1.3.2
oracle retail integration bus 15.0
oracle retail integration bus 15.0.4.0
oracle retail integration bus 16.0
oracle retail integration bus 16.0.3.0
oracle retail integration bus 19.0.1.0
oracle retail item planning 15.0.3
oracle retail macro space optimization 15.0.3
oracle retail merchandise financial planning 15.0.3
oracle retail merchandising system 19.0.1
oracle retail point-of-service 14.0
oracle retail point-of-service 14.1
oracle retail point-of-service 15.0
oracle retail point-of-service 16.0
oracle retail predictive application server 14.0.3
oracle retail predictive application server 14.1.3
oracle retail predictive application server 15.0.3
oracle retail predictive application server 16.0.3
oracle retail predictive application server 16.0.3.0
oracle retail regular price optimization 15.0.3
oracle retail regular price optimization 16.0.3
oracle retail replenishment optimization 15.0.3
oracle retail returns management 14.0
oracle retail returns management 14.1
oracle retail service backbone 14.1.3.2
oracle retail service backbone 15.0
oracle retail service backbone 15.0.4.0
oracle retail service backbone 16.0
oracle retail service backbone 16.0.3.0
oracle retail service backbone 19.0.1.0
oracle retail size profile optimization 15.0.3
oracle retail size profile optimization 16.0.3
oracle retail store inventory management 14.0.4
oracle retail store inventory management 14.1
oracle retail store inventory management 14.1.3
oracle retail store inventory management 15.0
oracle retail store inventory management 15.0.3
oracle retail store inventory management 16.0
oracle retail store inventory management 16.0.3
oracle retail xstore point of service 15.0.4
oracle retail xstore point of service 16.0.6
oracle retail xstore point of service 17.0.4
oracle retail xstore point of service 18.0.3
oracle retail xstore point of service 19.0.2
oracle timesten in-memory database *
oracle timesten in-memory database 11.2.2.8.49
oracle utilities framework 2.2.0.0.0
oracle utilities framework 4.2.0.2.0
oracle utilities framework 4.2.0.3.0
oracle utilities framework *
oracle utilities framework 4.4.0.0.0
oracle utilities framework 4.4.0.2.0
apache ant 1.1
apache ant 1.9.14
apache ant 1.10.0 -
apache ant 1.10.7 -
oracle retail point-of-service 14.0
oracle retail point-of-service 14.1
oracle flexcube investor servicing 12.1.0
oracle flexcube investor servicing 12.3.0
oracle primavera unifier 16.1
oracle primavera unifier 16.2
oracle flexcube private banking 12.0
oracle flexcube private banking 12.1
oracle retail store inventory management 14.0.4
oracle retail store inventory management 14.1.3
oracle retail back office 14.0
oracle retail back office 14.1
oracle retail predictive application server 14.0.3
oracle retail predictive application server 14.1.3
oracle retail returns management 14.1
oracle utilities framework 2.2.0.0.0
oracle utilities framework 4.2.0.2.0
oracle utilities framework 4.2.0.3.0
oracle utilities framework 4.3.0.3.0
oracle communications asap 7.3
oracle enterprise repository 11.1.1.7.0
oracle retail assortment planning 15.0.3
oracle communications metasolv solution 6.3.0
oracle flexcube investor servicing 12.4.0
ibm spectrum symphony 7.2.0.2
ibm spectrum symphony 7.1.2
oracle primavera unifier 17.12
oracle retail financial integration 15.0
oracle retail financial integration 16.0
oracle retail service backbone 15.0
oracle retail service backbone 16.0
oracle retail bulk data integration 16.0
oracle retail integration bus 14.1
oracle retail integration bus 15.0
oracle retail integration bus 16.0
oracle retail predictive application server 15.0.3
oracle retail central office 14.0
oracle retail central office 14.1
oracle retail returns management 14.0
oracle business process management suite 12.2.1.3.0
ibm platform symphony 7.1.1
ibm spectrum symphony 7.2.1
oracle primavera unifier 18.8
oracle flexcube investor servicing 14.0.0
ibm qradar security information and event manager 7.3.0
oracle flexcube investor servicing 14.1.0
ibm spectrum symphony 7.3
ibm log analysis 1.3.1
ibm log analysis 1.3.2
ibm log analysis 1.3.3
ibm log analysis 1.3.4
ibm log analysis 1.3.5
ibm log analysis 1.3.6
ibm qradar security information and event manager 7.3.3 p4
ibm qradar security information and event manager 7.4.0
ibm qradar security information and event manager 7.4.1 -
ibm control center 6.2.0.0
ibm cognos analytics 11.2.0
ibm cognos analytics 11.1.7
ibm business automation workflow 20.0.0.1
ibm business automation workflow 20.0.0.2
ibm business automation workflow 21.0.1
ibm case manager 5.3.3
ibm business automation workflow 22.0.1
ibm business automation workflow 21.0.3.1
ibm business automation workflow 22.0.2