CVE Feed

    Dashboard / CVE / CVE-2021-36374

    CVE-2021-36374

    When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.

    Published:Jul 13, 2021
    Last Modified:Aug 25, 2026
    EPS:Jul 14, 2021
    EPSS Score:0.02642
    CVSS Score:5.5

    Affected Products

    Vendor
    Apache
    Product
    Ant
    Vendor
    Oracle
    Product
    Agile Engineering Data Management
    Vendor
    Oracle
    Product
    Agile Product Lifecycle Management
    Vendor
    Oracle
    Product
    Banking Trade Finance
    Vendor
    Oracle
    Product
    Banking Treasury Management
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Automated Test Suite
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Binding Support Function
    Vendor
    Oracle
    Product
    Communications Diameter Intelligence Hub
    Vendor
    Oracle
    Product
    Communications Order And Service Management
    Vendor
    Oracle
    Product
    Communications Unified Inventory Management
    Vendor
    Oracle
    Product
    Enterprise Repository
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Health Sciences Information Manager
    Vendor
    Oracle
    Product
    Insurance Policy Administration
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Primavera Unifier
    Vendor
    Oracle
    Product
    Product Lifecycle Analytics
    Vendor
    Oracle
    Product
    Real-time Decision Server
    Vendor
    Oracle
    Product
    Retail Advanced Inventory Planning
    Vendor
    Oracle
    Product
    Retail Back Office
    Vendor
    Oracle
    Product
    Retail Bulk Data Integration
    Vendor
    Oracle
    Product
    Retail Central Office
    Vendor
    Oracle
    Product
    Retail Eftlink
    Vendor
    Oracle
    Product
    Retail Extract Transform And Load
    Vendor
    Oracle
    Product
    Retail Financial Integration
    Vendor
    Oracle
    Product
    Retail Integration Bus
    Vendor
    Oracle
    Product
    Retail Invoice Matching
    Vendor
    Oracle
    Product
    Retail Merchandising System
    Vendor
    Oracle
    Product
    Retail Point-of-service
    Vendor
    Oracle
    Product
    Retail Predictive Application Server
    Vendor
    Oracle
    Product
    Retail Service Backbone
    Vendor
    Oracle
    Product
    Retail Store Inventory Management
    Vendor
    Oracle
    Product
    Retail Xstore Point Of Service
    Vendor
    Oracle
    Product
    Timesten In-memory Database
    Vendor
    Oracle
    Product
    Utilities Framework
    Vendor
    Oracle
    Product
    Utilities Testing Accelerator

    Exploits

    No exploit reference

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High