5.5mediumMedium

CVE-2021-36374

Apache Ant

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, someone has to be persuaded to take an action first.

Scoring

CVSS
5.5 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weakness
CWE-130
Assigned by
security@apache.org

Dates

Published
2021-07-14
Last modified
2026-08-25
Sources
NVD

Affected products

  • Apache Ant1.9.0 - 1.9.16, 1.10.0 - 1.10.11
  • Oracle Agile Engineering Data Management6.2.1.0
  • Oracle Agile Product Lifecycle Management9.3.6
  • Oracle Banking Trade Finance14.5
  • Oracle Banking Treasury Management14.5
  • Oracle Communications Cloud Native Core Automated Test Suite1.9.0
  • Oracle Communications Cloud Native Core Binding Support Function1.11.0
  • Oracle Communications Diameter Intelligence Hub8.0.0 - 8.1.0, 8.2.0 - 8.2.3
  • Oracle Communications Order And Service Management7.3, 7.4
  • Oracle Communications Unified Inventory Management7.3.0, 7.4.0, 7.4.1, 7.4.2, 7.5.0
  • Oracle Enterprise Repository11.1.1.7.0
  • Oracle Financial Services Analytical Applications Infrastructure8.0.6 - 8.1.1

As listed in the NVD configuration data. Not a statement about your estate.

References