Resource exhaustion in Apache Ant - CVE-2021-36374
Published: July 14, 2021
Vulnerability identifier: #VU54856
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36374
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing ZIP archives. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Apache Ant
Arch Linux
Oracle Solaris Cluster
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
IBM Business Automation Workflow
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Real-Time Decision Server
Oracle Product Lifecycle Analytics
IBM Intelligent Operations Center
Oracle Communications Unified Inventory Management
Oracle Communications Diameter Intelligence Hub
Infrastructure Technology
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle Banking Treasury Management
Oracle Banking Trade Finance
Log Analysis
IBM Cloud Pak for Data System
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
Content Collector for IBM Connections
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Cloud Pak System
Oracle Health Sciences Information Manager
Oracle Utilities Framework
Oracle Agile Engineering Data Management
webMethods BPM
Oracle Application Testing Suite
Oracle Retail Xstore Point of Service
SecureTransport
Oracle Utilities Testing Accelerator
Oracle Enterprise Repository
Oracle Business Process Management Suite
Oracle Communications Order and Service Management
Oracle Agile PLM Framework
Oracle WebLogic Server
Primavera Gateway
Oracle Retail Merchandising System
Oracle Retail Invoice Matching
Oracle Retail EFTLink
Primavera Unifier
Oracle Retail Sales Audit
ant-apache-log4j
ant-swing
ant-scripts
ant-manual
ant-junit
ant-jmf
ant-jdepend
ant-javamail
ant-javadoc
ant-commons-logging
ant-apache-resolver
ant-apache-regexp
ant-apache-oro
ant-apache-bsf
ant-apache-bcel
ant-antlr
ant
ant-imageio
ant-commons-net
ant-apache-xalan2
ant-jsch
ant-junit5
ant-testutil
ant-xz
ant-help
ant-lib
IBM Case Manager
IBM InfoSphere Information Server
Arch Linux
Oracle Solaris Cluster
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
IBM Business Automation Workflow
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Real-Time Decision Server
Oracle Product Lifecycle Analytics
IBM Intelligent Operations Center
Oracle Communications Unified Inventory Management
Oracle Communications Diameter Intelligence Hub
Infrastructure Technology
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle Banking Treasury Management
Oracle Banking Trade Finance
Log Analysis
IBM Cloud Pak for Data System
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
Content Collector for IBM Connections
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Cloud Pak System
Oracle Health Sciences Information Manager
Oracle Utilities Framework
Oracle Agile Engineering Data Management
webMethods BPM
Oracle Application Testing Suite
Oracle Retail Xstore Point of Service
SecureTransport
Oracle Utilities Testing Accelerator
Oracle Enterprise Repository
Oracle Business Process Management Suite
Oracle Communications Order and Service Management
Oracle Agile PLM Framework
Oracle WebLogic Server
Primavera Gateway
Oracle Retail Merchandising System
Oracle Retail Invoice Matching
Oracle Retail EFTLink
Primavera Unifier
Oracle Retail Sales Audit
ant-apache-log4j
ant-swing
ant-scripts
ant-manual
ant-junit
ant-jmf
ant-jdepend
ant-javamail
ant-javadoc
ant-commons-logging
ant-apache-resolver
ant-apache-regexp
ant-apache-oro
ant-apache-bsf
ant-apache-bcel
ant-antlr
ant
ant-imageio
ant-commons-net
ant-apache-xalan2
ant-jsch
ant-junit5
ant-testutil
ant-xz
ant-help
ant-lib
IBM Case Manager
IBM InfoSphere Information Server
How to mitigate CVE-2021-36374
Install updates from vendor's website.
Apache Ant - addressed in versions 1.9.16, 1.10.11
IBM Cloud Pak System - update to 2.3.3.6
IBM Intelligent Operations Center - update to 5.2.3
SecureTransport - update to 5.5-20220825
webMethods BPM - update to 11.1 Fix 9
Primavera Gateway - addressed in versions 18.8.13, 19.12.12, 20.12.8
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
ant-apache-log4j - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-swing - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-scripts - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-manual - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-junit - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jmf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jdepend - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javamail - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javadoc - update to 1.9.4-3.9.1
ant-commons-logging - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-resolver - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-regexp - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-oro - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bsf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bcel - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-antlr - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-imageio - update to 1.10.7-150200.4.6.1
ant-commons-net - update to 1.10.7-150200.4.6.1
ant-apache-xalan2 - update to 1.10.7-150200.4.6.1
ant-jsch - update to 1.10.7-150200.4.6.1
ant-junit5 - update to 1.10.7-150200.4.6.1
ant-testutil - update to 1.10.7-150200.4.6.1
ant-xz - update to 1.10.7-150200.4.6.1
ant-commons-logging - update to 1.10.8-4
ant-jsch - update to 1.10.8-4
ant-antlr - update to 1.10.8-4
ant-apache-bsf - update to 1.10.8-4
ant-apache-xalan2 - update to 1.10.8-4
ant-apache-oro - update to 1.10.8-4
ant-javamail - update to 1.10.8-4
ant-apache-log4j - update to 1.10.8-4
ant-swing - update to 1.10.8-4
ant-xz - update to 1.10.8-4
ant-jmf - update to 1.10.8-4
ant-help - update to 1.10.8-4
ant-commons-net - update to 1.10.8-4
ant-junit - update to 1.10.8-4
ant-apache-bcel - update to 1.10.8-4
ant-jdepend - update to 1.10.8-4
ant-junit5 - update to 1.10.8-4
ant-testutil - update to 1.10.8-4
ant-lib - update to 1.10.8-4
ant-apache-regexp - update to 1.10.8-4
ant - update to 1.10.8-4
ant-imageio - update to 1.10.8-4
ant-apache-resolver - update to 1.10.8-4
IBM Cloud Pak for Data System - update to 2.0.2.1
Content Collector for Email - update to 4.0.1.15 IF001
Content Collector for File Systems - update to 4.0.1.15 IF001
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF001
Content Collector for IBM Connections - update to 4.0.1.15 IF001
IBM Case Manager - update to 5.3.3-IF011
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
IBM Cloud Pak System - update to 2.3.3.6
IBM Intelligent Operations Center - update to 5.2.3
SecureTransport - update to 5.5-20220825
webMethods BPM - update to 11.1 Fix 9
Primavera Gateway - addressed in versions 18.8.13, 19.12.12, 20.12.8
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
ant-apache-log4j - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-swing - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-scripts - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-manual - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-junit - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jmf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jdepend - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javamail - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javadoc - update to 1.9.4-3.9.1
ant-commons-logging - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-resolver - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-regexp - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-oro - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bsf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bcel - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-antlr - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-imageio - update to 1.10.7-150200.4.6.1
ant-commons-net - update to 1.10.7-150200.4.6.1
ant-apache-xalan2 - update to 1.10.7-150200.4.6.1
ant-jsch - update to 1.10.7-150200.4.6.1
ant-junit5 - update to 1.10.7-150200.4.6.1
ant-testutil - update to 1.10.7-150200.4.6.1
ant-xz - update to 1.10.7-150200.4.6.1
ant-commons-logging - update to 1.10.8-4
ant-jsch - update to 1.10.8-4
ant-antlr - update to 1.10.8-4
ant-apache-bsf - update to 1.10.8-4
ant-apache-xalan2 - update to 1.10.8-4
ant-apache-oro - update to 1.10.8-4
ant-javamail - update to 1.10.8-4
ant-apache-log4j - update to 1.10.8-4
ant-swing - update to 1.10.8-4
ant-xz - update to 1.10.8-4
ant-jmf - update to 1.10.8-4
ant-help - update to 1.10.8-4
ant-commons-net - update to 1.10.8-4
ant-junit - update to 1.10.8-4
ant-apache-bcel - update to 1.10.8-4
ant-jdepend - update to 1.10.8-4
ant-junit5 - update to 1.10.8-4
ant-testutil - update to 1.10.8-4
ant-lib - update to 1.10.8-4
ant-apache-regexp - update to 1.10.8-4
ant - update to 1.10.8-4
ant-imageio - update to 1.10.8-4
ant-apache-resolver - update to 1.10.8-4
IBM Cloud Pak for Data System - update to 2.0.2.1
Content Collector for Email - update to 4.0.1.15 IF001
Content Collector for File Systems - update to 4.0.1.15 IF001
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF001
Content Collector for IBM Connections - update to 4.0.1.15 IF001
IBM Case Manager - update to 5.3.3-IF011
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Ant
- Arch Linux update for ant
- Multiple vulnerabilities in Oracle Real-Time Decision Server
- Resource exhaustion in Oracle Enterprise Repository
- Multiple vulnerabilities in Oracle Utilities Testing Accelerator
- Multiple vulnerabilities in Oracle Communications Unified Inventory Management
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Multiple vulnerabilities in Oracle Communications Order and Service Management
- Multiple vulnerabilities in Oracle Communications Diameter Intelligence Hub
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Oracle Banking Treasury Management
- Multiple vulnerabilities in Oracle Banking Trade Finance
- Multiple vulnerabilities in Oracle Retail EFTLink
- Multiple vulnerabilities in Oracle Retail Invoice Matching
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Multiple vulnerabilities in Oracle Health Sciences Information Manager
- Multiple vulnerabilities in Oracle Product Lifecycle Analytics
- Multiple vulnerabilities in Oracle Agile Engineering Data Management
- Resource exhaustion in Oracle Utilities Framework
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in Primavera Gateway
- Resource exhaustion in IBM Intelligent Operations Center
- Multiple vulnerabilities in IBM Content Collector
- Resource exhaustion in Oracle Retail Sales Audit
- Multiple vulnerabilities in Oracle Retail Merchandising System
- SUSE update for ant
- SUSE update for ant
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in Axway SecureTransport (August 2022)
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in Middleware Common Libraries and Tools
- Multiple vulnerabilities in Oracle Application Testing Suite
- Resource exhaustion in Infrastructure Technology
- Multiple vulnerabilities in Oracle Business Process Management Suite
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Multiple vulnerabilities in IBM Application Performance Management
- openEuler update for ant
- Multiple vulnerabilities in Oracle Solaris Cluster
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in Oracle Middleware Common Libraries and Tools
- Multiple vulnerabilities in IBM webMethods BPM