Infinite loop in Apache Tika - CVE-2018-17197
Published: December 22, 2018 / Updated: December 24, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to an infinite loop when handling malicious input. A remote attacker can supply a carefully crafted or corrupt sqlite file, trigger and an infinite loop in Apache Tika's SQLite3Parser and cause the service to crash.
Affected software
Oracle Communications Instant Messaging Server
Oracle Knowledge
Oracle FLEXCUBE Private Banking
Primavera Unifier