CVE Feed

    Dashboard / CVE / CVE-2020-1945

    CVE-2020-1945

    Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

    Published:May 13, 2020
    Last Modified:Nov 21, 2024
    EPS:May 14, 2020
    EPSS Score:0.00021
    CVSS Score:6.3

    Affected Products

    Vendor
    Apache
    Product
    Ant
    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Opensuse
    Product
    Leap
    Vendor
    Oracle
    Product
    Agile Engineering Data Management
    Vendor
    Oracle
    Product
    Banking Enterprise Collections
    Vendor
    Oracle
    Product
    Banking Liquidity Management
    Vendor
    Oracle
    Product
    Banking Platform
    Vendor
    Oracle
    Product
    Business Process Management Suite
    Vendor
    Oracle
    Product
    Category Management Planning \& Optimization
    Vendor
    Oracle
    Product
    Communications Asap
    Vendor
    Oracle
    Product
    Communications Diameter Signaling Router
    Vendor
    Oracle
    Product
    Communications Metasolv Solution
    Vendor
    Oracle
    Product
    Communications Order And Service Management
    Vendor
    Oracle
    Product
    Data Integrator
    Vendor
    Oracle
    Product
    Endeca Information Discovery Studio
    Vendor
    Oracle
    Product
    Enterprise Manager Ops Center
    Vendor
    Oracle
    Product
    Enterprise Repository
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Flexcube Investor Servicing
    Vendor
    Oracle
    Product
    Flexcube Private Banking
    Vendor
    Oracle
    Product
    Health Sciences Information Manager
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Primavera Unifier
    Vendor
    Oracle
    Product
    Rapid Planning
    Vendor
    Oracle
    Product
    Real-time Decision Server
    Vendor
    Oracle
    Product
    Retail Advanced Inventory Planning
    Vendor
    Oracle
    Product
    Retail Assortment Planning
    Vendor
    Oracle
    Product
    Retail Back Office
    Vendor
    Oracle
    Product
    Retail Bulk Data Integration
    Vendor
    Oracle
    Product
    Retail Central Office
    Vendor
    Oracle
    Product
    Retail Data Extractor For Merchandising
    Vendor
    Oracle
    Product
    Retail Extract Transform And Load
    Vendor
    Oracle
    Product
    Retail Financial Integration
    Vendor
    Oracle
    Product
    Retail Integration Bus
    Vendor
    Oracle
    Product
    Retail Item Planning
    Vendor
    Oracle
    Product
    Retail Macro Space Optimization
    Vendor
    Oracle
    Product
    Retail Merchandise Financial Planning
    Vendor
    Oracle
    Product
    Retail Merchandising System
    Vendor
    Oracle
    Product
    Retail Point-of-service
    Vendor
    Oracle
    Product
    Retail Predictive Application Server
    Vendor
    Oracle
    Product
    Retail Regular Price Optimization
    Vendor
    Oracle
    Product
    Retail Replenishment Optimization
    Vendor
    Oracle
    Product
    Retail Returns Management
    Vendor
    Oracle
    Product
    Retail Service Backbone
    Vendor
    Oracle
    Product
    Retail Size Profile Optimization
    Vendor
    Oracle
    Product
    Retail Store Inventory Management
    Vendor
    Oracle
    Product
    Retail Xstore Point Of Service
    Vendor
    Oracle
    Product
    Timesten In-memory Database
    Vendor
    Oracle
    Product
    Utilities Framework
    Vendor
    Redhat
    Product
    Amq Streams
    Vendor
    Redhat
    Product
    Jboss Enterprise Bpms Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Brms Platform
    Vendor
    Redhat
    Product
    Openshift

    Exploits

    No exploit reference

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High