4.8
CVSSv3

CVE-2021-29425

Published: 13/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.8 | Impact Score: 2.5 | Exploitability Score: 2.2
VMScore: 517
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

In Apache Commons IO prior to 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache commons io 2.2

apache commons io 2.3

apache commons io 2.4

apache commons io 2.5

apache commons io 2.6

debian debian linux 9.0

oracle weblogic server 12.1.3.0.0

oracle retail integration bus 13.0

oracle flexcube core banking 5.2.0

oracle solaris cluster 4.0

oracle access manager 11.1.2.3.0

oracle weblogic server 12.2.1.3.0

oracle webcenter portal 12.2.1.3.0

oracle access manager 12.2.1.3.0

oracle application testing suite 13.3.0.1

oracle retail order broker 16.0

oracle banking platform 2.6.2

oracle primavera unifier 18.8

oracle primavera unifier

oracle agile plm 9.3.6

oracle banking digital experience 18.3

oracle banking digital experience 19.1

oracle banking digital experience 18.1

oracle weblogic server 12.2.1.4.0

oracle primavera unifier 19.12

oracle webcenter portal 12.2.1.4.0

oracle fusion middleware mapviewer 12.2.1.4.0

oracle weblogic server 14.1.1.0.0

oracle banking digital experience 19.2

oracle banking digital experience 20.1

oracle enterprise session border controller 8.4

oracle retail merchandising system 16.0.3

oracle banking platform 2.7.0

oracle banking platform 2.7.1

oracle agile engineering data management 6.2.1.0

oracle primavera unifier 20.12

oracle communications order and service management 7.4

oracle retail order broker 18.0

oracle insurance rules palette 11.0.2

oracle insurance rules palette 11.1.0

oracle communications billing and revenue management elastic charging engine 11.3

oracle communications billing and revenue management elastic charging engine 12.0

oracle communications interactive session recorder 6.3

oracle communications interactive session recorder 6.4

oracle commerce guided search 11.3.2

oracle insurance policy administration 11.3.0

oracle retail xstore point of service 17.0.4

oracle retail xstore point of service 18.0.3

oracle retail xstore point of service 19.0.2

oracle retail xstore point of service 20.0.1

oracle retail service backbone 15.0.3.1

oracle retail service backbone 14.1.3.2

oracle insurance policy administration 11.0.2

oracle communications cloud native core unified data repository 1.4.0

oracle retail order broker 19.1

oracle enterprise session border controller 9.0

oracle healthcare data repository 8.1.0

oracle communications application session controller 3.9.0

oracle communications converged application server - service controller 6.2

oracle flexcube core banking 11.10.0

oracle banking enterprise default management 2.12.0

oracle banking enterprise default management 2.10.0

oracle real user experience insight 13.4.1.0

oracle real user experience insight 13.5.1.0

oracle communications cloud native core network repository function 1.14.0

oracle banking party management 2.7.0

oracle retail merchandising system 19.0.1

oracle retail integration bus 14.1.3.2

oracle retail integration bus 15.0.3.1

oracle retail assortment planning 16.0.3

oracle communications order and service management 7.3

oracle retail size profile optimization 16.0.3

oracle access manager 12.2.1.4.0

oracle financial services analytical applications infrastructure

oracle communications pricing design center 12.0.0.4.0

oracle communications convergence 3.0.2.2.0

oracle primavera unifier 21.12

oracle utilities testing accelerator 6.0.0.2.2

oracle utilities testing accelerator 6.0.0.3.1

oracle utilities testing accelerator 6.0.0.1.1

oracle retail service backbone 19.0.0

oracle retail service backbone

oracle retail integration bus

oracle communications service broker 6.2

oracle banking digital experience 21.1

oracle banking apis 19.1

oracle banking apis 19.2

oracle banking apis 20.1

oracle banking apis 21.1

oracle communications cloud native core policy 1.14.0

oracle application performance management 13.5.1.0

oracle application performance management 13.4.1.0

oracle banking platform

oracle banking enterprise default managment

oracle banking apis 18.2

oracle banking digital experience 17.2

oracle banking apis 18.1

oracle banking apis 18.3

oracle communications design studio 7.3.5

oracle financial services model management and governance

oracle enterprise communications broker 3.3

oracle communications offline mediation controller 12.0.0.3

oracle oss support tools

oracle retail service backbone 14.1.3.0

oracle retail service backbone 19.0.1

oracle retail integration bus 14.1.3.0

oracle retail integration bus 19.0.0

oracle retail integration bus 19.0.1

oracle insurance rules palette 11.3.1

oracle insurance policy administration 11.1.0

oracle insurance policy administration 11.3.1

oracle banking enterprise default management 2.7.0

oracle banking enterprise default management 2.7.1

oracle banking enterprise default management 2.6.2

oracle insurance rules palette 11.3.0

oracle communications diameter intelligence hub

oracle insurance policy administration 11.2.8

oracle communications pricing design center 12.0.0.5.0

oracle blockchain platform

oracle insurance rules palette 11.2.8

oracle health sciences information manager

oracle helidon 2.2.0

oracle helidon 1.4.7

oracle communications policy management 12.5.0.0.0

oracle communications design studio

oracle communications contacts server 8.0.0.6.0

oracle rest data services

oracle rest data services 21.3

oracle health sciences data management workbench 2.5.2.1

oracle health sciences data management workbench 3.0.0.0

oracle retail pricing 19.0.1

oracle flexcube core banking

netapp active iq unified manager -

Vendor Advisories

Synopsis Moderate: Red Hat Decision Manager 7121 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed sever ...
Synopsis Moderate: Red Hat Process Automation Manager 7121 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gi ...
In Apache Commons IO before 27, When invoking the method FileNameUtilsnormalize with an improper input string, like "///foo", or "\\\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to const ...
No description is available for this CVE ...
In Apache Commons IO before 27, When invoking the method FileNameUtilsnormalize with an improper input string, like "///foo", or "\\\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to const ...
Multiple vulnerabilities have been found in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer Affected products and versions are listed below Please upgrade your version to the appropriate version To find fixed products, need to find same number following product name in [Affected products] and [Fixed products] ...

References

CWE-22https://issues.apache.org/jira/browse/IO-556https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00016.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://security.netapp.com/advisory/ntap-20220210-0004/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3Ehttps://nvd.nist.govhttps://access.redhat.com/errata/RHSA-2022:1110https://alas.aws.amazon.com/AL2/ALAS-2023-2059.html