First published: Tue Jul 13 2021(Updated: )
Apache Ant is vulnerable to a denial of service, caused by an out-of-memory error when large amounts of memory are allocated. By persuading a victim to open a specially-crafted TAR archive, a remote attacker could exploit this vulnerability to cause the application to crash.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Apache Ant | <1.9.16 | 1.9.16 |
redhat/Ant | <1.10.11 | 1.10.11 |
Apache Ant | >=1.9.0<1.9.16 | |
Apache Ant | >=1.10.0<1.10.11 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Banking Trade Finance | =14.5 | |
Oracle Banking Treasury Management | =14.5 | |
Oracle Communications Cloud Native Core Automated Test Suite | =1.9.0 | |
Oracle Communications Cloud Native Core Binding Support Function | =1.11.0 | |
Oracle Communications Order and Service Management | =7.3 | |
Oracle Communications Order and Service Management | =7.4 | |
Oracle Communications Unified Inventory Management | =7.3.0 | |
Oracle Communications Unified Inventory Management | =7.4.0 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle Communications Unified Inventory Management | =7.4.2 | |
Oracle Communications Unified Inventory Management | =7.5.0 | |
Oracle Enterprise Repository | =11.1.1.7.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6<=8.1.1 | |
Oracle Insurance Policy Administration | >=11.0<=11.3.1 | |
Oracle Primavera Gateway | >=17.12.0<=17.12.11 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.12 | |
Oracle Primavera Gateway | >=19.12.0<=19.12.11 | |
Oracle Primavera Gateway | >=20.12.0<=20.12.7 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Primavera Unifier | =20.12 | |
Oracle Real-time Decision Server | =3.2.0.0 | |
Oracle Real-time Decision Server | =11.1.1.9.0 | |
Oracle Retail Advanced Inventory Planning | =14.1 | |
Oracle Retail Advanced Inventory Planning | =15.0 | |
Oracle Retail Advanced Inventory Planning | =16.0 | |
Oracle Retail Back Office | =14.0 | |
Oracle Retail Back Office | =14.1 | |
Oracle Retail Bulk Data Integration | =16.0.3.0 | |
Oracle Retail Bulk Data Integration | =19.0.1 | |
Oracle Retail Central Office | =14.0 | |
Oracle Retail Central Office | =14.1 | |
Oracle Retail Eftlink | =19.0.1 | |
Oracle Retail Eftlink | =20.0.1 | |
Oracle Retail Extract Transform And Load | =13.2.8 | |
Oracle Retail Financial Integration | =14.1.3.2 | |
Oracle Retail Financial Integration | =15.0.4.0 | |
Oracle Retail Financial Integration | =16.0.3.0 | |
Oracle Retail Integration Bus | =14.1.3.2 | |
Oracle Retail Integration Bus | =15.0.4.0 | |
Oracle Retail Integration Bus | =16.0.3.0 | |
Oracle Retail Integration Bus | =19.0.1.0 | |
Oracle Retail Invoice Matching | =16.0.3 | |
Oracle Retail Merchandising System | =19.0.1 | |
Oracle Retail Point-of-Service | =14.0 | |
Oracle Retail Point-of-Service | =14.1 | |
Oracle Retail Predictive Application Server | =14.1.3 | |
Oracle Retail Predictive Application Server | =15.0.3 | |
Oracle Retail Predictive Application Server | =16.0.3.0 | |
Oracle Retail Service Backbone | =14.1.3.2 | |
Oracle Retail Service Backbone | =15.0.4.0 | |
Oracle Retail Service Backbone | =16.0.3.0 | |
Oracle Retail Service Backbone | =19.0.1.0 | |
Oracle Retail Store Inventory Management | =14.1 | |
Oracle Retail Store Inventory Management | =15.0 | |
Oracle Retail Store Inventory Management | =16.0 | |
Oracle Retail Xstore Point of Service | =16.0.6 | |
Oracle Retail Xstore Point of Service | =17.0.4 | |
Oracle Retail Xstore Point of Service | =18.0.3 | |
Oracle Retail Xstore Point of Service | =19.0.2 | |
Oracle Retail Xstore Point of Service | =20.0.1 | |
Oracle TimesTen In-Memory Database | <11.2.2.8.27 | |
Oracle Utilities Framework | >=4.3.0.1.0<=4.3.0.6.0 | |
Oracle Utilities Framework | =4.2.0.2.0 | |
Oracle Utilities Framework | =4.2.0.3.0 | |
Oracle Utilities Framework | =4.4.0.0.0 | |
Oracle Utilities Framework | =4.4.0.2.0 | |
Oracle Utilities Framework | =4.4.0.3.0 | |
Oracle Utilities Testing Accelerator | =6.0.0.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability ID CVE-2021-36373 is a denial of service vulnerability in Apache Ant.
Vulnerability CVE-2021-36373 occurs when a specially crafted TAR archive is read by an Apache Ant build.
The impact of vulnerability CVE-2021-36373 is a denial of service caused by an out-of-memory error that can disrupt builds using Apache Ant.
Vulnerability CVE-2021-36373 affects Apache Ant versions prior to 1.9.16 and 1.10.11.
To mitigate vulnerability CVE-2021-36373, it is recommended to update Apache Ant to version 1.9.16 or 1.10.11.