cbcvebase.
CVE-2021-30129
published 2021-07-12

CVE-2021-30129: A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port…

PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
3.39%
87.5th percentile
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

Affected

15 ranges
VendorProductVersion rangeFixed in
apachesshd>= 2.0.0 < 2.7.02.7.0
apache_software_foundationapache_mina_sshd>= 2.0.0 < Apache Mina SSHD*Apache Mina SSHD*
debianlibmina-sshd-java
oraclebanking_payments
oraclebanking_trade_finance
oraclebanking_treasury_management
oraclecommunications_cloud_native_core_console
oracleflexcube_universal_banking
oracleflexcube_universal_banking14.0.0 – 14.3.0
oraclemiddleware_common_libraries_and_tools
oraclemiddleware_common_libraries_and_tools
oraclemiddleware_common_libraries_and_tools
oracleoss_support_tools
oracleretail_customer_management_and_segmentation_foundation
oracleretail_customer_management_and_segmentation_foundation

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_debian6.5LOW
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.