Resource exhaustion in Apache Ant - CVE-2021-36374

 

Resource exhaustion in Apache Ant - CVE-2021-36374

Published: July 14, 2021


Vulnerability identifier: #VU54856
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36374
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when processing ZIP archives. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Apache Ant
Arch Linux
Oracle Solaris Cluster
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
IBM Business Automation Workflow
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Binding Support Function
Oracle Real-Time Decision Server
Oracle Product Lifecycle Analytics
IBM Intelligent Operations Center
Oracle Communications Unified Inventory Management
Oracle Communications Diameter Intelligence Hub
Infrastructure Technology
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle Banking Treasury Management
Oracle Banking Trade Finance
Log Analysis
IBM Cloud Pak for Data System
Content Collector for Email
Content Collector for File Systems
Content Collector for Microsoft SharePoint
Content Collector for IBM Connections
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Cloud Pak System
Oracle Health Sciences Information Manager
Oracle Utilities Framework
Oracle Agile Engineering Data Management
webMethods BPM
Oracle Application Testing Suite
Oracle Retail Xstore Point of Service
SecureTransport
Oracle Utilities Testing Accelerator
Oracle Enterprise Repository
Oracle Business Process Management Suite
Oracle Communications Order and Service Management
Oracle Agile PLM Framework
Oracle WebLogic Server
Primavera Gateway
Oracle Retail Merchandising System
Oracle Retail Invoice Matching
Oracle Retail EFTLink
Primavera Unifier
Oracle Retail Sales Audit
ant-apache-log4j
ant-swing
ant-scripts
ant-manual
ant-junit
ant-jmf
ant-jdepend
ant-javamail
ant-javadoc
ant-commons-logging
ant-apache-resolver
ant-apache-regexp
ant-apache-oro
ant-apache-bsf
ant-apache-bcel
ant-antlr
ant
ant-imageio
ant-commons-net
ant-apache-xalan2
ant-jsch
ant-junit5
ant-testutil
ant-xz
ant-help
ant-lib
IBM Case Manager
IBM InfoSphere Information Server

How to mitigate CVE-2021-36374

Install updates from vendor's website.

Apache Ant - addressed in versions 1.9.16, 1.10.11
IBM Cloud Pak System - update to 2.3.3.6
IBM Intelligent Operations Center - update to 5.2.3
SecureTransport - update to 5.5-20220825
webMethods BPM - update to 11.1 Fix 9
Primavera Gateway - addressed in versions 18.8.13, 19.12.12, 20.12.8
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
ant-apache-log4j - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-swing - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-scripts - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-manual - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-junit - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jmf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-jdepend - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javamail - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-javadoc - update to 1.9.4-3.9.1
ant-commons-logging - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-resolver - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-regexp - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-oro - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bsf - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-apache-bcel - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-antlr - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant - addressed in versions 1.9.4-3.9.1, 1.10.7-150200.4.6.1
ant-imageio - update to 1.10.7-150200.4.6.1
ant-commons-net - update to 1.10.7-150200.4.6.1
ant-apache-xalan2 - update to 1.10.7-150200.4.6.1
ant-jsch - update to 1.10.7-150200.4.6.1
ant-junit5 - update to 1.10.7-150200.4.6.1
ant-testutil - update to 1.10.7-150200.4.6.1
ant-xz - update to 1.10.7-150200.4.6.1
ant-commons-logging - update to 1.10.8-4
ant-jsch - update to 1.10.8-4
ant-antlr - update to 1.10.8-4
ant-apache-bsf - update to 1.10.8-4
ant-apache-xalan2 - update to 1.10.8-4
ant-apache-oro - update to 1.10.8-4
ant-javamail - update to 1.10.8-4
ant-apache-log4j - update to 1.10.8-4
ant-swing - update to 1.10.8-4
ant-xz - update to 1.10.8-4
ant-jmf - update to 1.10.8-4
ant-help - update to 1.10.8-4
ant-commons-net - update to 1.10.8-4
ant-junit - update to 1.10.8-4
ant-apache-bcel - update to 1.10.8-4
ant-jdepend - update to 1.10.8-4
ant-junit5 - update to 1.10.8-4
ant-testutil - update to 1.10.8-4
ant-lib - update to 1.10.8-4
ant-apache-regexp - update to 1.10.8-4
ant - update to 1.10.8-4
ant-imageio - update to 1.10.8-4
ant-apache-resolver - update to 1.10.8-4
IBM Cloud Pak for Data System - update to 2.0.2.1
Content Collector for Email - update to 4.0.1.15 IF001
Content Collector for File Systems - update to 4.0.1.15 IF001
Content Collector for Microsoft SharePoint - update to 4.0.1.15 IF001
Content Collector for IBM Connections - update to 4.0.1.15 IF001
IBM Case Manager - update to 5.3.3-IF011
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4

External References

Related Security Bulletins