Resource exhaustion in Apache Ant - CVE-2021-36373
Published: July 14, 2021
Vulnerability identifier: #VU54855
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-36373
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing TAR archives. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Apache Ant
IBM Business Automation Workflow
IBM Intelligent Operations Center
Log Analysis
IBM Cloud Pak for Data System
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
Content Collector for IBM Connections
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Arch Linux
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
IBM Cloud Pak System
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JD Edwards EnterpriseOne Tools
webMethods BPM
ant-apache-oro
ant-swing
ant-scripts
ant-manual
ant-junit
ant-jmf
ant-jdepend
ant-javamail
ant-javadoc
ant-commons-logging
ant-apache-resolver
ant-apache-regexp
ant-apache-log4j
ant-apache-bsf
ant-apache-bcel
ant-antlr
ant
ant-imageio
ant-commons-net
ant-testutil
ant-jsch
ant-junit5
ant-apache-xalan2
ant-xz
ant-lib
ant-help
IBM Case Manager
IBM InfoSphere Information Server
IBM Business Automation Workflow
IBM Intelligent Operations Center
Log Analysis
IBM Cloud Pak for Data System
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
Content Collector for IBM Connections
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Arch Linux
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
IBM Cloud Pak System
SecureTransport
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JD Edwards EnterpriseOne Tools
webMethods BPM
ant-apache-oro
ant-swing
ant-scripts
ant-manual
ant-junit
ant-jmf
ant-jdepend
ant-javamail
ant-javadoc
ant-commons-logging
ant-apache-resolver
ant-apache-regexp
ant-apache-log4j
ant-apache-bsf
ant-apache-bcel
ant-antlr
ant
ant-imageio
ant-commons-net
ant-testutil
ant-jsch
ant-junit5
ant-apache-xalan2
ant-xz
ant-lib
ant-help
IBM Case Manager
IBM InfoSphere Information Server
How to mitigate CVE-2021-36373
Install updates from vendor's website.
Apache Ant - addressed in versions 1.9.16, 1.10.11
IBM Cloud Pak System - update to 2.3.3.6
IBM Intelligent Operations Center - update to 5.2.3
SecureTransport - update to 5.5-20220825
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.0
JD Edwards EnterpriseOne Tools - update to 9.2.7.3
webMethods BPM - update to 11.1 Fix 9
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
ant-apache-oro - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-swing - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-scripts - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-manual - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-junit - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jmf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jdepend - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javamail - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javadoc - update to 1.9.4-3.9.1
ant-commons-logging - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-resolver - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-regexp - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-log4j - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bsf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bcel - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-antlr - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-imageio - update to 1.10.7-150200.4.6.1
ant-commons-net - update to 1.10.7-150200.4.6.1
ant-testutil - update to 1.10.7-150200.4.6.1
ant-jsch - update to 1.10.7-150200.4.6.1
ant-junit5 - update to 1.10.7-150200.4.6.1
ant-apache-xalan2 - update to 1.10.7-150200.4.6.1
ant-xz - update to 1.10.7-150200.4.6.1
ant-apache-oro - update to 1.10.8-4
ant-lib - update to 1.10.8-4
ant-apache-xalan2 - update to 1.10.8-4
ant-javamail - update to 1.10.8-4
ant-apache-log4j - update to 1.10.8-4
ant-commons-logging - update to 1.10.8-4
ant-apache-resolver - update to 1.10.8-4
ant-junit - update to 1.10.8-4
ant-apache-bsf - update to 1.10.8-4
ant-antlr - update to 1.10.8-4
ant-jsch - update to 1.10.8-4
ant-xz - update to 1.10.8-4
ant-jmf - update to 1.10.8-4
ant-help - update to 1.10.8-4
ant-commons-net - update to 1.10.8-4
ant-apache-regexp - update to 1.10.8-4
ant - update to 1.10.8-4
ant-apache-bcel - update to 1.10.8-4
ant-jdepend - update to 1.10.8-4
ant-junit5 - update to 1.10.8-4
ant-testutil - update to 1.10.8-4
ant-swing - update to 1.10.8-4
ant-imageio - update to 1.10.8-4
IBM Cloud Pak for Data System - update to 2.0.2.1
Content Collector for Email - update to 4.0.1.15 IF001
Content Collector for File Systems - update to 4.0.1.15 IF001
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF001
Content Collector for IBM Connections - update to 4.0.1.15 IF001
IBM Case Manager - update to 5.3.3-IF011
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
IBM Cloud Pak System - update to 2.3.3.6
IBM Intelligent Operations Center - update to 5.2.3
SecureTransport - update to 5.5-20220825
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.0
JD Edwards EnterpriseOne Tools - update to 9.2.7.3
webMethods BPM - update to 11.1 Fix 9
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
ant-apache-oro - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-swing - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-scripts - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-manual - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-junit - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jmf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jdepend - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javamail - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javadoc - update to 1.9.4-3.9.1
ant-commons-logging - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-resolver - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-regexp - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-log4j - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bsf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bcel - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-antlr - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-imageio - update to 1.10.7-150200.4.6.1
ant-commons-net - update to 1.10.7-150200.4.6.1
ant-testutil - update to 1.10.7-150200.4.6.1
ant-jsch - update to 1.10.7-150200.4.6.1
ant-junit5 - update to 1.10.7-150200.4.6.1
ant-apache-xalan2 - update to 1.10.7-150200.4.6.1
ant-xz - update to 1.10.7-150200.4.6.1
ant-apache-oro - update to 1.10.8-4
ant-lib - update to 1.10.8-4
ant-apache-xalan2 - update to 1.10.8-4
ant-javamail - update to 1.10.8-4
ant-apache-log4j - update to 1.10.8-4
ant-commons-logging - update to 1.10.8-4
ant-apache-resolver - update to 1.10.8-4
ant-junit - update to 1.10.8-4
ant-apache-bsf - update to 1.10.8-4
ant-antlr - update to 1.10.8-4
ant-jsch - update to 1.10.8-4
ant-xz - update to 1.10.8-4
ant-jmf - update to 1.10.8-4
ant-help - update to 1.10.8-4
ant-commons-net - update to 1.10.8-4
ant-apache-regexp - update to 1.10.8-4
ant - update to 1.10.8-4
ant-apache-bcel - update to 1.10.8-4
ant-jdepend - update to 1.10.8-4
ant-junit5 - update to 1.10.8-4
ant-testutil - update to 1.10.8-4
ant-swing - update to 1.10.8-4
ant-imageio - update to 1.10.8-4
IBM Cloud Pak for Data System - update to 2.0.2.1
Content Collector for Email - update to 4.0.1.15 IF001
Content Collector for File Systems - update to 4.0.1.15 IF001
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF001
Content Collector for IBM Connections - update to 4.0.1.15 IF001
IBM Case Manager - update to 5.3.3-IF011
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Ant
- Arch Linux update for ant
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Denial of service in IBM Intelligent Operations Center
- Multiple vulnerabilities in IBM Content Collector
- SUSE update for ant
- SUSE update for ant
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in Axway SecureTransport (August 2022)
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Multiple vulnerabilities in IBM Application Performance Management
- openEuler update for ant
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM webMethods BPM