cbcvebase.
CVE-2021-27807
published 2021-03-19

CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
apachepdfbox2.0.0 – 2.0.22
apachetika
apache_software_foundationapache_pdfboxApache PDFBox – 2.0.22
debianlibpdfbox-java< libpdfbox2-java 2.0.23-1 (bookworm)libpdfbox2-java 2.0.23-1 (bookworm)
debianlibpdfbox2-java< libpdfbox2-java 2.0.23-1 (bookworm)libpdfbox2-java 2.0.23-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_treasury_management
oraclebanking_virtual_account_management
oraclebanking_virtual_account_management
oraclebanking_virtual_account_management
oraclecommunications_messaging_server
oraclecommunications_session_report_manager8.0.0 – 8.2.4.0
oracleflexcube_universal_banking
oracleflexcube_universal_banking14.0.0 – 14.3.0
oraclehyperion_financial_reporting
oraclehyperion_financial_reporting
oraclehyperion_infrastructure_technology< 11.2.8.011.2.8.0
oracleoutside_in_technology
oracleprimavera_unifier
oracleprimavera_unifier

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM