CVE-2021-41616
Last modified
CVE-2021-41616 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used ObjectInputStream.readObject without validating that the input data was safe to deserialize. EPSS estimates a 3.21% chance of exploitation in the next 30 days.
Description
Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used ObjectInputStream.readObject without validating that the input data was safe to deserialize. Please note that DdlUtils is no longer being actively developed. To address the insecurity of the BinaryObjectHelper class, the following changes to DdlUtils have been made: (1) BinaryObjectsHelper.java has been deleted from the DdlUtils source repository and the DdlUtils feature of propagating data of SQL binary types is therefore no longer present in DdlUtils; (2) The ddlutils-1.0 release has been removed from the Apache Release Distribution Infrastructure; (3) The DdlUtils web site has been updated to indicate that DdlUtils is now available only as source code, not as a packaged release.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ddlutils | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41616?
How severe is CVE-2021-41616?
How do I fix CVE-2021-41616?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41610Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-41611An issue was discovered in Squid 5.0.6 through 5.1.x before …7.5
- CVE-2021-41612An issue was discovered in the ALU unit of the OpenRISC mor1…8.8
- CVE-2021-41613An issue was discovered in the controller unit of the OpenRI…4.3
- CVE-2021-41614An issue was discovered in the controller unit of the OpenRI…7.8
- CVE-2021-41615websda.c in GoAhead WebServer 2.1.8 has insufficient nonce e…9.8
- CVE-2021-41617sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non…7
- CVE-2021-41619An issue was discovered in Gradle Enterprise before 2021.1.2…7.2
- CVE-2021-4162archivy is vulnerable to Cross-Site Request Forgery (CSRF)4.3
- CVE-2021-41634A user enumeration vulnerability in MELAG FTP Server 2.2.0.4…5.3
- CVE-2021-41635When installed as Windows service MELAG FTP Server 2.2.0.4 i…8.8
- CVE-2021-41636MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD c…6.5
Are you affected by CVE-2021-41616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
