Improper Handling of Length Parameter Inconsistency in Apache Commons Compress - CVE-2021-33517
Published: April 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists because during reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. A remote attacker can trigger the vulnerability and perform a denial of service (DoS) attack.
Affected software
IBM WebSphere Application Server Liberty
How to mitigate CVE-2021-33517
IBM WebSphere Application Server Liberty - update to 21.0.0.10