CVE-2021-41973

MEDIUMCVSS 6.5/10EPSS 4.33%

Last modified

CVE-2021-41973 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. EPSS estimates a 4.33% chance of exploitation in the next 30 days.

Description

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
4.33%

90.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheMina< 2.0.22
ApacheMina>= 2.1.0, < 2.1.5
OracleBanking Payments14.5
OracleBanking Trade Finance Process Management14.5
OracleBanking Treasury Management14.5
OracleCommunications Cloud Native Core Console1.9.0
OracleCustomer Management And Segmentation Foundation18.0
OracleCustomer Management And Segmentation Foundation19.0
OracleFlexcube Universal Banking>= 14.0, <= 14.3
OracleFlexcube Universal Banking14.5
OracleFusion Middleware Common Libraries And Tools12.2.1.3.0
OracleFusion Middleware Common Libraries And Tools12.2.1.4.0
OracleFusion Middleware Common Libraries And Tools14.1.1.0.0
OracleOss Support Tools2.12.42

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-41973?
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
How severe is CVE-2021-41973?
CVE-2021-41973 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 4.33% probability of exploitation in the next 30 days.
How do I fix CVE-2021-41973?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-41973?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST