cbcvebase.
CVE-2021-27568
published 2021-02-23

CVE-2021-27568: An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.89%
85.3th percentile
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

Affected

13 ranges
VendorProductVersion rangeFixed in
json-smart_projectjson-smart-v1< 1.3.21.3.2
json-smart_projectjson-smart-v2< 2.3.12.3.1
json-smart_projectjson-smart-v2>= 2.4 < 2.4.12.4.1
oraclecommunications_cloud_native_core_policy
oracleoss_support_tools< 2.12.422.12.42
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_oracle9.1MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.