CVE-2020-1945

MEDIUMCVSS 6.3/10EPSS 1.79%

Last modified

CVE-2020-1945 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.. EPSS estimates a 1.79% chance of exploitation in the next 30 days.

Description

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

Metrics

CVSS 3.1
6.3/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Probability
1.79%

75.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheAnt>= 1.1, <= 1.9.14
ApacheAnt>= 1.10.0, <= 1.10.7
CanonicalUbuntu Linux19.10
FedoraprojectFedora31
FedoraprojectFedora32
OpensuseLeap15.2
OracleAgile Engineering Data Management6.2.1.0
OracleBanking Enterprise Collections>= 2.7.0, <= 2.9.0
OracleBanking Liquidity Management>= 14.0.0, <= 14.4.0
OracleBanking Platform>= 2.4.0, <= 2.9.0
OracleBusiness Process Management Suite12.2.1.3.0
OracleBusiness Process Management Suite12.2.1.4.0
OracleCategory Management Planning \& Optimization15.0.3
OracleCommunications Asap7.3
OracleCommunications Diameter Signaling Router>= 8.0.0, <= 8.2.2
OracleCommunications Metasolv Solution6.3.0
OracleCommunications Order And Service Management7.3
OracleCommunications Order And Service Management7.4
OracleData Integrator12.2.1.3.0
OracleData Integrator12.2.1.4.0
OracleEndeca Information Discovery Studio3.2.0
OracleEnterprise Manager Ops Center12.4.0.0
OracleEnterprise Repository11.1.1.7.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6, <= 8.1.0
OracleFlexcube Investor Servicing12.1.0
OracleFlexcube Investor Servicing12.3.0
OracleFlexcube Investor Servicing12.4.0
OracleFlexcube Investor Servicing14.0.0
OracleFlexcube Investor Servicing14.1.0
OracleFlexcube Private Banking12.0.0
OracleFlexcube Private Banking12.1.0
OracleHealth Sciences Information Manager>= 3.0, <= 3.0.2
OraclePrimavera Gateway>= 16.2.0, <= 16.2.11
OraclePrimavera Gateway>= 17.12.0, <= 17.12.7
OraclePrimavera Unifier>= 17.7, <= 17.12
OraclePrimavera Unifier16.1
OraclePrimavera Unifier16.2
OraclePrimavera Unifier18.8
OraclePrimavera Unifier19.12
OracleRapid Planning12.1
OracleRapid Planning12.2
OracleReal-Time Decision Server3.2.1.0
OracleRetail Advanced Inventory Planning14.1
OracleRetail Advanced Inventory Planning15.0
OracleRetail Advanced Inventory Planning16.0
OracleRetail Assortment Planning15.0.3
OracleRetail Assortment Planning16.0.3
OracleRetail Back Office14.0
OracleRetail Back Office14.1
OracleRetail Bulk Data Integration15.0

Showing 50 of 117 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-1945?
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
How severe is CVE-2020-1945?
CVE-2020-1945 has a CVSS score of 6.3/10 (MEDIUM severity). The EPSS model estimates a 1.79% probability of exploitation in the next 30 days.
How do I fix CVE-2020-1945?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-1945?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST