5.5
CVSSv3

CVE-2020-9489

Published: 27/04/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tika 1.24

oracle flexcube private banking 12.1.0

oracle primavera unifier 16.2

oracle flexcube private banking 12.0.0

oracle primavera unifier 16.1

oracle webcenter portal 12.2.1.3.0

oracle primavera unifier 18.8

oracle primavera unifier

oracle primavera unifier 19.12

oracle webcenter portal 12.2.1.4.0

oracle communications messaging server 8.1

Vendor Advisories

Synopsis Important: Red Hat Fuse 780 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 77 to 78) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...
Debian Bug report logs - #984666 CVE-2020-9489 Package: src:tika; Maintainer for src:tika is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 6 Mar 2021 20:00:01 UTC Severity: important Tags: security Reply or subscribe to this ...