CVE-2021-30129
Last modified
CVE-2021-30129 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. EPSS estimates a 3.39% chance of exploitation in the next 30 days.
Description
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Sshd | >= 2.0.0, < 2.7.0 |
| Oracle | Banking Payments | 14.5 |
| Oracle | Banking Trade Finance | 14.5 |
| Oracle | Banking Treasury Management | 14.5 |
| Oracle | Communications Cloud Native Core Console | 1.9.0 |
| Oracle | Flexcube Universal Banking | >= 14.0.0, <= 14.3.0 |
| Oracle | Flexcube Universal Banking | 14.5 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.3.0 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.4.0 |
| Oracle | Middleware Common Libraries And Tools | 14.1.1.0.0 |
| Oracle | Oss Support Tools | 2.12.42 |
| Oracle | Retail Customer Management And Segmentation Foundation | 18.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 19.0 |
References
- http://www.openwall.com/lists/oss-security/2021/07/12/1Mailing List, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/07/12/1Mailing List, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-30129?
How severe is CVE-2021-30129?
How do I fix CVE-2021-30129?
Are you affected by CVE-2021-30129?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
