← All CVEs

CVE-2021-35515

high · 7.5

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

7.5
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2021-07-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-834CWE-835

Affected products

VendorProductAffected versions
apachecommons_compress>= 1.6, <= 1.20
netappactive_iq_unified_managerall versions
netappactive_iq_unified_managerall versions
netappactive_iq_unified_managerall versions
netapponcommand_insightall versions
oraclebanking_digital_experience>= 18.1, <= 18.3
oraclebanking_digital_experience19.1
oraclebanking_digital_experience20.1
oraclebanking_digital_experience21.1
oraclebanking_enterprise_default_management2.7.0
oraclebanking_party_management2.7.0
oraclebanking_payments14.5
oraclebanking_trade_finance14.5
oraclebanking_treasury_management14.5
oraclebusiness_process_management_suite12.2.1.3.0
oraclebusiness_process_management_suite12.2.1.4.0
oraclecommerce_guided_search11.3.2
oraclecommunications_billing_and_revenue_management12.0.0.4
oraclecommunications_cloud_native_core_automated_test_suite1.8.0
oraclecommunications_cloud_native_core_service_communication_proxy1.14.0
oraclecommunications_cloud_native_core_unified_data_repository1.14.0
oraclecommunications_diameter_intelligence_hub>= 8.0.0, <= 8.2.3
oraclecommunications_session_route_manager>= 8.0.0, <= 8.2.5
oraclefinancial_services_crime_and_compliance_management_studio8.0.8.2.0
oraclefinancial_services_crime_and_compliance_management_studio8.0.8.3.0
oraclefinancial_services_enterprise_case_management8.0.7.2.0
oraclefinancial_services_enterprise_case_management8.0.8.1.0
oracleflexcube_universal_banking>= 14.0.0, <= 14.3.0
oracleflexcube_universal_banking12.4.0
oracleflexcube_universal_banking14.5.0
oraclehealthcare_data_repository8.1.0
oracleinsurance_policy_administration11.0.2
oracleinsurance_policy_administration11.1.0
oracleinsurance_policy_administration11.2.8
oracleinsurance_policy_administration11.3.0
oracleinsurance_policy_administration11.3.1
oraclepeoplesoft_enterprise_peopletools8.57
oraclepeoplesoft_enterprise_peopletools8.58
oraclepeoplesoft_enterprise_peopletools8.59
oracleprimavera_unifier>= 17.7, <= 17.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-35515