A malicious SCP peer can trigger the issue by sending a command line that never terminates with an LF character. The CVSS vector indicates that network access and low privileges are required, with no user interaction.
Deployments using the sshd-scp component are affected if they run Apache MINA SSHD before 2.20.0, or versions 3.0.0-M1 through 3.0.0-M5. Apache MINA SSHD is used for both client-side and server-side SSH, so either role may be exposed when it processes SCP protocol input.
The vulnerable SCP protocol handler continues allocating memory for an unterminated command line. This can exhaust application memory and cause an OutOfMemoryError, resulting in denial of service.
Upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6. These versions enforce an upper limit on SCP protocol-line length.