First published: Fri Apr 24 2020(Updated: )
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9489">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9489</a> <a href="http://seclists.org/oss-sec/2020/q2/69">http://seclists.org/oss-sec/2020/q2/69</a> <a href="https://lists.apache.org/thread.html/r4d943777e36ca3aa6305a45da5acccc54ad894f2d5a07186cfa2442c%40%3Cdev.tika.apache.org%3E">https://lists.apache.org/thread.html/r4d943777e36ca3aa6305a45da5acccc54ad894f2d5a07186cfa2442c%40%3Cdev.tika.apache.org%3E</a>
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | =1.24 | |
Oracle FLEXCUBE Private Banking | =12.0.0 | |
Oracle FLEXCUBE Private Banking | =12.1.0 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =16.1 | |
Oracle Primavera Unifier | =16.2 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
Sun iPlanet Messaging Server | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9489 is a vulnerability in Apache Tika that allows a carefully crafted or corrupt file to trigger a System.exit in Tika's OneNote Parser, causing the application to exit unexpectedly.
CVE-2020-9489 affects Apache Tika versions 1.24, Oracle FLEXCUBE Private Banking versions 12.0.0 and 12.1.0, Oracle Primavera Unifier versions 16.1, 16.2, 18.8, and 19.12, Oracle WebCenter Portal versions 12.2.1.3.0 and 12.2.1.4.0, and Oracle Communications Messaging Server version 8.1.
CVE-2020-9489 has a severity rating of 5.5 out of 10, which is categorized as medium severity.
To fix CVE-2020-9489, Apache Tika users should upgrade to the latest version available.
A carefully crafted or corrupt file can trigger a System.exit in Tika's OneNote Parser, causing the application to exit.