CVE-2021-29425
published 2021-04-13CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result…
PriorityP335medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
10.23%
95.4th percentile
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Affected
139 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_io | — | — |
| apache | commons_io | — | — |
| apache | commons_io | — | — |
| apache | commons_io | — | — |
| apache | commons_io | — | — |
| apache_software_foundation | apache_commons_io | — | — |
| apache_software_foundation | apache_commons_io | — | — |
| apache_software_foundation | apache_commons_io | — | — |
| apache_software_foundation | apache_commons_io | — | — |
| apache_software_foundation | apache_commons_io | — | — |
| debian | commons-io | < commons-io 2.8.0-1 (bookworm) | commons-io 2.8.0-1 (bookworm) |
| debian | debian_linux | — | — |
| oracle | access_manager | — | — |
| oracle | access_manager | — | — |
| oracle | access_manager | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | application_performance_management | — | — |
| oracle | application_performance_management | — | — |
| oracle | application_testing_suite | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv4.8MEDIUM
vendor_oracle5.3MEDIUM
vendor_debian4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Communications Offline Mediation Controller 12.0.0.3 Installation path traversal (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Offline Mediation Controller 12.0.0.3 Installation path traversal (WID-SEC-2023-1359)
A vulnerability labeled as critical has been found in Oracle Communications Offline Mediation Controller 12.0.0.3. This issue affects some unknown processing of the component Installation. The manipulation results in path traversal.
This vulnerability was named CVE-2021-29425. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
VulDB
Oracle Communications Convergence 3.0.2.2.0 Convergence Server path traversal (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Convergence 3.0.2.2.0 Convergence Server path traversal (WID-SEC-2023-1359)
A vulnerability identified as critical has been detected in Oracle Communications Convergence 3.0.2.2.0. This vulnerability affects unknown code of the component Convergence Server. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2021-29425. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
VulDB
Oracle Hyperion Financial Management 11.1.2.4/11.2.6.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Hyperion Financial Management 11.1.2.4/11.2.6.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability was found in Oracle Hyperion Financial Management 11.1.2.4/11.2.6.0 and classified as critical. This affects an unknown function of the component Apache Commons IO. Such manipulation leads to information disclosure.
This vulnerability is traded as CVE-2021-29425. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications Cloud Native Core Unified Data Repository UDR path traversal (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Cloud Native Core Unified Data Repository UDR path traversal (WID-SEC-2023-1359)
A vulnerability labeled as critical has been found in Oracle Communications Cloud Native Core Unified Data Repository 1.14.0. Affected by this vulnerability is an unknown functionality of the component UDR. The manipulation results in path traversal.
This vulnerability is reported as CVE-2021-29425. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
VulDB
Oracle Retail Customer Management and Segmentation Foundation Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Retail Customer Management and Segmentation Foundation Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability, which was classified as critical, has been found in Oracle Retail Customer Management and Segmentation Foundation up to 19.0. Impacted is an unknown function of the component Apache Commons IO. Performing a manipulation results in information disclosure.
This vulnerability is known as CVE-2021-29425. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
VulDB
Oracle Commerce Guided Search 11.3.2 Content Acquisition System path traversal (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Commerce Guided Search 11.3.2 Content Acquisition System path traversal (WID-SEC-2023-1359)
A vulnerability identified as critical has been detected in Oracle Commerce Guided Search 11.3.2. This affects an unknown function of the component Content Acquisition System. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2021-29425. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
VulDB
Oracle Communications BRM - Elastic Charging Engine 12.0 Charging Controller path traversal (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications BRM - Elastic Charging Engine 12.0 Charging Controller path traversal (WID-SEC-2023-1359)
A vulnerability categorized as critical has been discovered in Oracle Communications BRM - Elastic Charging Engine 12.0. This affects an unknown part of the component Charging Controller. Executing a manipulation can lead to path traversal.
This vulnerability is handled as CVE-2021-29425. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
VulDB
Oracle MySQL Enterprise Monitor up to 8.0.25 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle MySQL Enterprise Monitor up to 8.0.25 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability was found in Oracle MySQL Enterprise Monitor up to 8.0.25 and classified as critical. Affected by this issue is some unknown functionality of the component Apache Commons IO. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2021-29425. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle PeopleSoft Enterprise PeopleTools 8.57/8.58 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle PeopleSoft Enterprise PeopleTools 8.57/8.58 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability was found in Oracle PeopleSoft Enterprise PeopleTools 8.57/8.58 and classified as critical. This affects an unknown part of the component Apache Commons IO. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2021-29425. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications Cloud Native Core Network Repository Function NRF path traversal (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Cloud Native Core Network Repository Function NRF path traversal (WID-SEC-2023-1359)
A vulnerability identified as critical has been detected in Oracle Communications Cloud Native Core Network Repository Function 1.14.0. Affected is an unknown function of the component NRF. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2021-29425. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
VulDB
Oracle Documaker up to 12.6.4 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-28·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Documaker up to 12.6.4 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability categorized as critical has been discovered in Oracle Documaker 12.6.0/12.6.1/12.6.2/12.6.3/12.6.4. This issue affects some unknown processing of the component Apache Commons IO. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2021-29425. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
VulDB
Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability was found in Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0. It has been classified as critical. The affected element is an unknown function of the component Apache Commons IO. This manipulation causes information disclosure.
This vulnerability is handled as CVE-2021-29425. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Communications Calendar Server 8.0.0.6.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Calendar Server 8.0.0.6.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability identified as critical has been detected in Oracle Communications Calendar Server 8.0.0.6.0. Affected by this issue is some unknown functionality of the component Apache Commons IO. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2021-29425. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
VulDB
Oracle Communications MetaSolv Solution 6.3.1 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications MetaSolv Solution 6.3.1 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability marked as critical has been reported in Oracle Communications MetaSolv Solution 6.3.1. This vulnerability affects unknown code of the component Apache Commons IO. Performing a manipulation results in information disclosure.
This vulnerability is identified as CVE-2021-29425. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Real-Time Decision Server 3.2.0.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Real-Time Decision Server 3.2.0.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability was found in Oracle Real-Time Decision Server 3.2.0.0 and classified as critical. Impacted is an unknown function of the component Apache Commons IO. The manipulation results in information disclosure.
This vulnerability is known as CVE-2021-29425. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications Application Session Controller 3.9 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Application Session Controller 3.9 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability was found in Oracle Communications Application Session Controller 3.9 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Apache Commons IO. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2021-29425. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Apache Commons IO up to 2.6 FileNameUtils.normalize path traversal (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Apache Commons IO up to 2.6 FileNameUtils.normalize path traversal (WID-SEC-2023-1359)
A vulnerability identified as critical has been detected in Apache Commons IO up to 2.6. Affected by this issue is the function FileNameUtils.normalize. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2021-29425. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
VulDB
Oracle Communications Session Route Manager up to 8.2.5.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Session Route Manager up to 8.2.5.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability labeled as critical has been found in Oracle Communications Session Route Manager up to 8.2.5.0. The affected element is an unknown function of the component Apache Commons IO. The manipulation results in information disclosure.
This vulnerability is known as CVE-2021-29425. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
VulDB
Oracle Communications Converged Application Server - Service Controller Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Converged Application Server - Service Controller Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability was found in Oracle Communications Converged Application Server - Service Controller 6.2. It has been classified as critical. Affected by this issue is some unknown functionality of the component Apache Commons IO. This manipulation causes information disclosure.
This vulnerability is registered as CVE-2021-29425. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
VulDB
Oracle GoldenGate Application Adapters 19.1.0.0.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle GoldenGate Application Adapters 19.1.0.0.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability has been found in Oracle GoldenGate Application Adapters 19.1.0.0.0 and classified as critical. This issue affects some unknown processing of the component Apache Commons IO. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2021-29425. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
VulDB
Oracle Communications Messaging Server 8.1 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Messaging Server 8.1 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability labeled as critical has been found in Oracle Communications Messaging Server 8.1. This affects an unknown part of the component Apache Commons IO. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2021-29425. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
VulDB
Oracle Primavera Gateway up to 17.12.11/18.8.12/19.12.11 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Primavera Gateway up to 17.12.11/18.8.12/19.12.11 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability marked as critical has been reported in Oracle Primavera Gateway up to 17.12.11/18.8.12/19.12.11. Affected is an unknown function of the component Apache Commons IO. Performing a manipulation results in information disclosure.
This vulnerability is known as CVE-2021-29425. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
VulDB
Oracle Communications Session Report Manager up to 8.2.5.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
vuldb·2026-08-27·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Communications Session Report Manager up to 8.2.5.0 Apache Commons IO information disclosure (WID-SEC-2023-1359)
A vulnerability categorized as critical has been discovered in Oracle Communications Session Report Manager up to 8.2.5.0. This issue affects some unknown processing of the component Apache Commons IO. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2021-29425. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
OSV
Path Traversal and Improper Input Validation in Apache Commons IO
osv·2021-04-26
CVE-2021-29425 [MEDIUM] Path Traversal and Improper Input Validation in Apache Commons IO
Path Traversal and Improper Input Validation in Apache Commons IO
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
GHSA
Path Traversal and Improper Input Validation in Apache Commons IO
ghsa·2021-04-26
CVE-2021-29425 [MEDIUM] CWE-20 Path Traversal and Improper Input Validation in Apache Commons IO
Path Traversal and Improper Input Validation in Apache Commons IO
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
OSV
CVE-2021-29425: In Apache Commons IO before 2
osv·2021-04-13·CVSS 4.8
CVE-2021-29425 [MEDIUM] CVE-2021-29425: In Apache Commons IO before 2
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Oracle
Oracle Oracle Communications Risk Matrix: Security (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2024-07-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Communications Risk Matrix: Security (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Communications Risk Matrix: Security (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Hyperion Risk Matrix: Security (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2024-01-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Hyperion Risk Matrix: Security (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Hyperion Risk Matrix: Security (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2023-07-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2023-04-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Utilities Applications Risk Matrix: System Wide (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2023-01-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Utilities Applications Risk Matrix: System Wide (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Utilities Applications Risk Matrix: System Wide (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2022-10-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Securities (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2022-07-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Securities (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Financial Services Applications Risk Matrix: Securities (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2022-04-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2022-01-15·CVSS 4.8
CVE-2021-29425 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 4.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Administration (Apache Commons IO) — CVE-2021-29425
vendor_oracle·2021-10-15·CVSS 5.3
CVE-2021-29425 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Administration (Apache Commons IO) — CVE-2021-29425
Oracle Oracle Communications Applications Risk Matrix: Administration (Apache Commons IO) vulnerability
CVE: CVE-2021-29425
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Ubuntu
Apache Commons IO vulnerability
vendor_ubuntu·2021-09-29
CVE-2021-29425 Apache Commons IO vulnerability
Title: Apache Commons IO vulnerability
Summary: Apache Commons IO could be made to expose sensitive information if it
received a specially crafted input.
It was discovered that Apache Commons IO incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6
vendor_redhat·2021-04-12·CVSS 4.8
CVE-2021-29425 [MEDIUM] CWE-22 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6
apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Statement: While the apache-commons-io package included in Red Hat Enterprise Linux 8 Maven App Stream contains the vulnerable code, it is not used in any way by Maven or other packages in this module. This package is not an API component of Maven, thus the affected code can not be reached in any supported scenario.
Package: commons-io (A-MQ Clients 2)
Debian
CVE-2021-29425: commons-io - In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normaliz...
vendor_debian·2021·CVSS 4.8
CVE-2021-29425 [MEDIUM] CVE-2021-29425: commons-io - In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normaliz...
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Scope: local
bookworm: resolved (fixed in 2.8.0-1)
bullseye: resolved (fixed in 2.8.0-1)
forky: resolved (fixed in 2.8.0-1)
sid: resolved (fixed in 2.8.0-1)
trixie: resolved (fixed in 2.8.0-1)
No detection rules found.
No public exploits indexed.
arXiv
PPT4J: Patch Presence Test for Java Binaries
arxiv_fulltext·2024-01-15
PPT4J: Patch Presence Test for Java Binaries
## Abstract
The number of vulnerabilities reported in open source software has increased substantially in recent years. Security patches provide the necessary measures to protect software from attacks and vulnerabilities. In practice, it is difficult to identify whether patches have been integrated into software, especially if we only have binary files. Therefore, the ability to test whether a patch is applied to the target binary, a.k.a. patch presence test, is crucial for practitioners. However, it is challenging to obtain accurate semantic information from patches, which could lead to incorrect results.
In this paper, we propose a new patch presence test framework named ( ). is designed for open-source Java libraries. It takes Java binaries (i.e. bytecode files) as input, extracts sem
arXiv
How well does LLM generate security tests?
arxiv_fulltext·2023-10-03
How well does LLM generate security tests?
How well does LLM generate security tests?
## Abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. People refer to such attacks as supply chain attacks, the documented number of which has increased 742% in 2022. People created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they ask for code or evidence to demonstrate how library vulnerabilities lead to
arXiv
Security Review of Ethereum Beacon Clients
arxiv_fulltext·2021-09-23
Security Review of Ethereum Beacon Clients
center
[width=7cm]beacon
empty
1cm
Security Review of Ethereum Beacon Clients
1cm
JP Aumasson -- Taurus, Switzerland -- [email protected],
Denis Kolegov -- Tomsk State University, Russia -- [email protected]
Evangelia Stathopoulou -- University College London, UK -- [email protected]
0.5cm
Version
0.5cm
Supported by the Ethereum Foundation.
center
## Abstract
The beacon chain is the backbone of the Ethereum's evolution
towards a proof-of-stake-based scalable network.
Beacon clients are the applications implementing the services
required to operate the beacon chain, namely validators, beacon
nodes, and slashers.
Security defects in beacon clients could lead to loss of funds,
consensus rules violation, network congestion, and other
inconveniences.
We repo
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle October 2021 Critical Patch Update Addresses 231 CVEs
blogs_tenable·2021-10-20
Oracle October 2021 Critical Patch Update Addresses 231 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6
bugzilla·2021-04-12·CVSS 4.8
CVE-2021-29425 [MEDIUM] CVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6
CVE-2021-29425 apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6
In Apache Commons IO before 2.7, When invoking the method
FileNameUtils.normalize with an improper input string, like
"//../foo", or "\\..\foo", the result would be the same value, thus
possibly providing access to files in the parent directory, but not
further above (thus "limited" path traversal), if the calling code
would use the result to construct a path value.
References:
https://www.openwall.com/lists/oss-security/2021/04/12/1
https://issues.apache.org/jira/browse/IO-556
Discussion:
This issue has been addressed in the following products:
Vert.x 4.1.0
Via RHSA-2021:2465 https://access.redhat.com/errata/RHSA-2021:2465
---
This bug is now closed. Further updates for individual products wi
https://issues.apache.org/jira/browse/IO-556https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00016.htmlhttps://security.netapp.com/advisory/ntap-20220210-0004/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://issues.apache.org/jira/browse/IO-556https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3Ehttps://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3Ehttps://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3Ehttps://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/08/msg00016.htmlhttps://security.netapp.com/advisory/ntap-20220210-0004/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-04-13
Published