CVE-2021-35515
high · 7.5When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
7.5
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2021-07-13
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-834CWE-835
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | commons_compress | >= 1.6, <= 1.20 |
| netapp | active_iq_unified_manager | all versions |
| netapp | active_iq_unified_manager | all versions |
| netapp | active_iq_unified_manager | all versions |
| netapp | oncommand_insight | all versions |
| oracle | banking_digital_experience | >= 18.1, <= 18.3 |
| oracle | banking_digital_experience | 19.1 |
| oracle | banking_digital_experience | 20.1 |
| oracle | banking_digital_experience | 21.1 |
| oracle | banking_enterprise_default_management | 2.7.0 |
| oracle | banking_party_management | 2.7.0 |
| oracle | banking_payments | 14.5 |
| oracle | banking_trade_finance | 14.5 |
| oracle | banking_treasury_management | 14.5 |
| oracle | business_process_management_suite | 12.2.1.3.0 |
| oracle | business_process_management_suite | 12.2.1.4.0 |
| oracle | commerce_guided_search | 11.3.2 |
| oracle | communications_billing_and_revenue_management | 12.0.0.4 |
| oracle | communications_cloud_native_core_automated_test_suite | 1.8.0 |
| oracle | communications_cloud_native_core_service_communication_proxy | 1.14.0 |
| oracle | communications_cloud_native_core_unified_data_repository | 1.14.0 |
| oracle | communications_diameter_intelligence_hub | >= 8.0.0, <= 8.2.3 |
| oracle | communications_session_route_manager | >= 8.0.0, <= 8.2.5 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
| oracle | financial_services_enterprise_case_management | 8.0.7.2.0 |
| oracle | financial_services_enterprise_case_management | 8.0.8.1.0 |
| oracle | flexcube_universal_banking | >= 14.0.0, <= 14.3.0 |
| oracle | flexcube_universal_banking | 12.4.0 |
| oracle | flexcube_universal_banking | 14.5.0 |
| oracle | healthcare_data_repository | 8.1.0 |
| oracle | insurance_policy_administration | 11.0.2 |
| oracle | insurance_policy_administration | 11.1.0 |
| oracle | insurance_policy_administration | 11.2.8 |
| oracle | insurance_policy_administration | 11.3.0 |
| oracle | insurance_policy_administration | 11.3.1 |
| oracle | peoplesoft_enterprise_peopletools | 8.57 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | peoplesoft_enterprise_peopletools | 8.59 |
| oracle | primavera_unifier | >= 17.7, <= 17.12 |
Check a specific version with /api/v1/cve/match.
References
- http://www.openwall.com/lists/oss-security/2021/07/13/1
- https://commons.apache.org/proper/commons-compress/security-reports.html
- https://lists.apache.org/thread.html/r19ebfd71770ec0617a9ea180e321ef927b3fefb4c81ec5d1902d20ab%40%3Cuser.commons.apache.org%3E
- https://lists.apache.org/thread.html/r67ef3c07fe3b8c1b02d48012149d280ad6da8e4cec253b527520fb2b%40%3Cdev.poi.apache.org%3E
- https://lists.apache.org/thread.html/r9f54c0caa462267e0cc68b49f141e91432b36b23348d18c65bd0d040%40%3Cnotifications.skywalking.apache.org%3E
- https://lists.apache.org/thread.html/rab292091eadd1ecc63c516e9541a7f241091cf2e652b8185a6059945%40%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/racd0c0381c8404f298b226cd9db2eaae965b14c9c568224aa3f437ae%40%3Cnotifications.skywalking.apache.org%3E
- https://lists.apache.org/thread.html/rb064d705fdfa44b5dae4c366b369ef6597951083196321773b983e71%40%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rb6e1fa80d34e5ada45f72655d84bfd90db0ca44ef19236a49198c88c%40%3Cnotifications.skywalking.apache.org%3E
- https://lists.apache.org/thread.html/rb7adf3e55359819e77230b4586521e5c6874ce5ed93384bdc14d6aee%40%3Cnotifications.skywalking.apache.org%3E
- https://lists.apache.org/thread.html/rba65ed5ddb0586f5b12598f55ec7db3633e7b7fede60466367fbf86a%40%3Cnotifications.skywalking.apache.org%3E
- https://lists.apache.org/thread.html/rbaea15ddc5a7c0c6b66660f1d6403b28595e2561bb283eade7d7cd69%40%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rbe91c512c5385181149ab087b6c909825d34299f5c491c6482a2ed57%40%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rd4332baaf6debd03d60deb7ec93bee49e5fdbe958cb6800dff7fb00e%40%3Cnotifications.skywalking.apache.org%3E
- https://lists.apache.org/thread.html/rf2f4d7940371a7c7c5b679f50e28fc7fcc82cd00670ced87e013ac88%40%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rfba19167efc785ad3561e7ef29f340d65ac8f0d897aed00e0731e742%40%3Cnotifications.skywalking.apache.org%3E
- https://security.netapp.com/advisory/ntap-20211022-0001/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- http://www.openwall.com/lists/oss-security/2021/07/13/1
- https://commons.apache.org/proper/commons-compress/security-reports.html
- https://lists.apache.org/thread.html/r19ebfd71770ec0617a9ea180e321ef927b3fefb4c81ec5d1902d20ab%40%3Cuser.commons.apache.org%3E
- https://lists.apache.org/thread.html/r67ef3c07fe3b8c1b02d48012149d280ad6da8e4cec253b527520fb2b%40%3Cdev.poi.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-35515