Vulnerability Name: | CVE-2021-36373 (CCN-205311) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2021-07-13 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2021-07-13 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2023-02-28 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | Apache Ant is vulnerable to a denial of service, caused by an out-of-memory error when large amounts of memory are allocated. By persuading a victim to open a specially-crafted TAR archive, a remote attacker could exploit this vulnerability to cause the application to crash. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-36373 Source: CCN Type: Apache Web site Apache Ant Source: security@apache.org Type: Patch, Vendor Advisory security@apache.org Source: XF Type: UNKNOWN apache-cve202136373-dos(205311) Source: security@apache.org Type: Mailing List, Vendor Advisory security@apache.org Source: security@apache.org Type: Mailing List, Vendor Advisory security@apache.org Source: security@apache.org Type: Mailing List, Vendor Advisory security@apache.org Source: security@apache.org Type: Mailing List, Vendor Advisory security@apache.org Source: security@apache.org Type: Mailing List, Vendor Advisory security@apache.org Source: CCN Type: oss-sec Mailing List, Tue, 13 Jul 2021 17:15:27 +0000 CVE-2021-36373: Apache Ant TAR archive denial of service vulnerability Source: security@apache.org Type: Third Party Advisory security@apache.org Source: CCN Type: IBM Security Bulletin 6514443 (Tivoli Netcool/Impact) IBM Tivoli Netcool Impact is affected by an Apache Ant vulnerability (CVE-2021-36373) Source: CCN Type: IBM Security Bulletin 6518994 (Installation Manager) Vulnerabilities in Apache Ant affect IBM Installation Manager and IBM Packaging Utility Source: CCN Type: IBM Security Bulletin 6570915 (Data Risk Manager) IBM Data Risk Manager is affected by multiple vulnerabilities including a remote code execution in Spring Framework (CVE-2022-22965) Source: CCN Type: IBM Security Bulletin 6570957 (Cognos Analytics) IBM Cognos Analytics has addressed multiple vulnerabilities Source: CCN Type: IBM Security Bulletin 6619109 (Intelligent Operations Center) A vulnerability foud in IBM Installation Manager which is shipped with IBM Intelligent Operations Center(CVE-2021-36373) Source: CCN Type: IBM Security Bulletin 6825111 (Content Collector) Multiple Vulnerabilities may affect Apache Ant used by Content Collector for Email, Content Collector for File Systems, Content Collector for Microsoft SharePoint and Content Collector for IBM Connections Source: CCN Type: IBM Security Bulletin 6829339 (InfoSphere Information Server) Multiple vulnerabilities in Apache Ant affect IBM InfoSphere Information Server Source: security@apache.org Type: Patch, Third Party Advisory security@apache.org Source: security@apache.org Type: Patch, Third Party Advisory security@apache.org Source: security@apache.org Type: Not Applicable security@apache.org Source: security@apache.org Type: Patch, Third Party Advisory security@apache.org | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |