Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-29425


In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.


Published

2021-04-13T07:15:12.327

Last Modified

2024-11-21T06:01:04.113

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache commons_io 2.2 Yes
Application apache commons_io 2.3 Yes
Application apache commons_io 2.4 Yes
Application apache commons_io 2.5 Yes
Application apache commons_io 2.6 Yes
Operating System debian debian_linux 9.0 Yes
Application oracle access_manager 11.1.2.3.0 Yes
Application oracle access_manager 12.2.1.3.0 Yes
Application oracle access_manager 12.2.1.4.0 Yes
Application oracle agile_engineering_data_management 6.2.1.0 Yes
Application oracle agile_plm 9.3.6 Yes
Application oracle application_performance_management 13.4.1.0 Yes
Application oracle application_performance_management 13.5.1.0 Yes
Application oracle application_testing_suite 13.3.0.1 Yes
Application oracle banking_apis 18.1 Yes
Application oracle banking_apis 18.2 Yes
Application oracle banking_apis 18.3 Yes
Application oracle banking_apis 19.1 Yes
Application oracle banking_apis 19.2 Yes
Application oracle banking_apis 20.1 Yes
Application oracle banking_apis 21.1 Yes
Application oracle banking_digital_experience 17.2 Yes
Application oracle banking_digital_experience 18.1 Yes
Application oracle banking_digital_experience 18.3 Yes
Application oracle banking_digital_experience 19.1 Yes
Application oracle banking_digital_experience 19.2 Yes
Application oracle banking_digital_experience 20.1 Yes
Application oracle banking_digital_experience 21.1 Yes
Application oracle banking_enterprise_default_management 2.6.2 Yes
Application oracle banking_enterprise_default_management 2.7.0 Yes
Application oracle banking_enterprise_default_management 2.7.1 Yes
Application oracle banking_enterprise_default_management 2.10.0 Yes
Application oracle banking_enterprise_default_management 2.12.0 Yes
Application oracle banking_enterprise_default_managment ≤ 2.4.0 Yes
Application oracle banking_party_management 2.7.0 Yes
Application oracle banking_platform ≤ 2.4.1 Yes
Application oracle banking_platform 2.6.2 Yes
Application oracle banking_platform 2.7.0 Yes
Application oracle banking_platform 2.7.1 Yes
Application oracle blockchain_platform < 21.1.2 Yes
Application oracle commerce_guided_search 11.3.2 Yes
Application oracle communications_application_session_controller 3.9.0 Yes
Application oracle communications_billing_and_revenue_management_elastic_charging_engine 11.3 Yes
Application oracle communications_billing_and_revenue_management_elastic_charging_engine 12.0 Yes
Application oracle communications_cloud_native_core_network_repository_function 1.14.0 Yes
Application oracle communications_cloud_native_core_policy 1.14.0 Yes
Application oracle communications_cloud_native_core_unified_data_repository 1.4.0 Yes
Application oracle communications_contacts_server 8.0.0.6.0 Yes
Application oracle communications_converged_application_server_-_service_controller 6.2 Yes
Application oracle communications_convergence 3.0.2.2.0 Yes
Application oracle communications_design_studio ≤ 7.4.2 Yes
Application oracle communications_design_studio 7.3.5 Yes
Application oracle communications_diameter_intelligence_hub ≤ 8.1.0 Yes
Application oracle communications_diameter_intelligence_hub ≤ 8.2.3 Yes
Application oracle communications_interactive_session_recorder 6.3 Yes
Application oracle communications_interactive_session_recorder 6.4 Yes
Application oracle communications_offline_mediation_controller 12.0.0.3 Yes
Application oracle communications_order_and_service_management 7.3 Yes
Application oracle communications_order_and_service_management 7.4 Yes
Application oracle communications_policy_management 12.5.0.0.0 Yes
Application oracle communications_pricing_design_center 12.0.0.4.0 Yes
Application oracle communications_pricing_design_center 12.0.0.5.0 Yes
Application oracle communications_service_broker 6.2 Yes
Application oracle enterprise_communications_broker 3.3 Yes
Application oracle enterprise_session_border_controller 8.4 Yes
Application oracle enterprise_session_border_controller 9.0 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 8.1.1 Yes
Application oracle financial_services_model_management_and_governance ≤ 8.1.1 Yes
Application oracle flexcube_core_banking ≤ 11.8.0 Yes
Application oracle flexcube_core_banking 5.2.0 Yes
Application oracle flexcube_core_banking 11.10.0 Yes
Application oracle fusion_middleware_mapviewer 12.2.1.4.0 Yes
Application oracle health_sciences_data_management_workbench 2.5.2.1 Yes
Application oracle health_sciences_data_management_workbench 3.0.0.0 Yes
Application oracle health_sciences_information_manager ≤ 3.0.4 Yes
Application oracle healthcare_data_repository 8.1.0 Yes
Application oracle helidon 1.4.7 Yes
Application oracle helidon 2.2.0 Yes
Application oracle insurance_policy_administration 11.0.2 Yes
Application oracle insurance_policy_administration 11.1.0 Yes
Application oracle insurance_policy_administration 11.2.8 Yes
Application oracle insurance_policy_administration 11.3.0 Yes
Application oracle insurance_policy_administration 11.3.1 Yes
Application oracle insurance_rules_palette 11.0.2 Yes
Application oracle insurance_rules_palette 11.1.0 Yes
Application oracle insurance_rules_palette 11.2.8 Yes
Application oracle insurance_rules_palette 11.3.0 Yes
Application oracle insurance_rules_palette 11.3.1 Yes
Application oracle oss_support_tools < 2.12.42 Yes
Application oracle primavera_unifier ≤ 17.12 Yes
Application oracle primavera_unifier 18.8 Yes
Application oracle primavera_unifier 19.12 Yes
Application oracle primavera_unifier 20.12 Yes
Application oracle primavera_unifier 21.12 Yes
Application oracle real_user_experience_insight 13.4.1.0 Yes
Application oracle real_user_experience_insight 13.5.1.0 Yes
Application oracle rest_data_services < 21.2 Yes
Application oracle rest_data_services 21.3 Yes
Application oracle retail_assortment_planning 16.0.3 Yes
Application oracle retail_integration_bus ≤ 16.0.3 Yes
Application oracle retail_integration_bus 13.0 Yes
Application oracle retail_integration_bus 14.1.3.0 Yes
Application oracle retail_integration_bus 14.1.3.2 Yes
Application oracle retail_integration_bus 15.0.3.1 Yes
Application oracle retail_integration_bus 19.0.0 Yes
Application oracle retail_integration_bus 19.0.1 Yes
Application oracle retail_merchandising_system 16.0.3 Yes
Application oracle retail_merchandising_system 19.0.1 Yes
Application oracle retail_order_broker 16.0 Yes
Application oracle retail_order_broker 18.0 Yes
Application oracle retail_order_broker 19.1 Yes
Application oracle retail_pricing 19.0.1 Yes
Application oracle retail_service_backbone ≤ 16.0.3 Yes
Application oracle retail_service_backbone 14.1.3.0 Yes
Application oracle retail_service_backbone 14.1.3.2 Yes
Application oracle retail_service_backbone 15.0.3.1 Yes
Application oracle retail_service_backbone 19.0.0 Yes
Application oracle retail_service_backbone 19.0.1 Yes
Application oracle retail_size_profile_optimization 16.0.3 Yes
Application oracle retail_xstore_point_of_service 17.0.4 Yes
Application oracle retail_xstore_point_of_service 18.0.3 Yes
Application oracle retail_xstore_point_of_service 19.0.2 Yes
Application oracle retail_xstore_point_of_service 20.0.1 Yes
Application oracle solaris_cluster 4.0 Yes
Application oracle utilities_testing_accelerator 6.0.0.1.1 Yes
Application oracle utilities_testing_accelerator 6.0.0.2.2 Yes
Application oracle utilities_testing_accelerator 6.0.0.3.1 Yes
Application oracle webcenter_portal 12.2.1.3.0 Yes
Application oracle webcenter_portal 12.2.1.4.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes

References