cbcvebase.
CVE-2021-41973
published 2021-11-01

CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

Affected

17 ranges
VendorProductVersion rangeFixed in
apachemina< 2.0.222.0.22
apachemina>= 2.1.0 < 2.1.52.1.5
apache_software_foundationapache_mina>= Apache MINA < 2.1.52.1.5
debianmina< mina2 2.1.5-1 (bookworm)mina2 2.1.5-1 (bookworm)
debianmina2< mina2 2.1.5-1 (bookworm)mina2 2.1.5-1 (bookworm)
oraclebanking_payments
oraclebanking_trade_finance_process_management
oraclebanking_treasury_management
oraclecommunications_cloud_native_core_console
oraclecustomer_management_and_segmentation_foundation
oraclecustomer_management_and_segmentation_foundation
oracleflexcube_universal_banking
oracleflexcube_universal_banking14.0 – 14.3
oraclefusion_middleware_common_libraries_and_tools
oraclefusion_middleware_common_libraries_and_tools
oraclefusion_middleware_common_libraries_and_tools
oracleoss_support_tools

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM