DNA View

CVE-2020-1950

Medium
Low Medium High Critical
5.5
CVSS Score
Published: Mar 23, 2020
Last Modified: Nov 21, 2024

Vulnerability Description

A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
L
Attack Complexity
L
Privileges Required
N
User Interaction
R
Scope
U
Confidentiality
N
Integrity
N
Availability
H

Known Affected Software

8 configuration(s) from 3 vendor(s)

ubuntu_linux
Version:
16.04
CPE:
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:*:*:*:*
debian_linux
Version:
8.0
CPE:
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
flexcube_private_banking
Version:
12.1.0
CPE:
cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
communications_messaging_server
Version:
8.0.2
CPE:
cpe:2.3:a:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*
flexcube_private_banking
Version:
12.0.0
CPE:
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
business_process_management_suite
Version:
12.2.1.3.0
CPE:
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*
communications_messaging_server
Version:
8.1
CPE:
cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
business_process_management_suite
Version:
12.2.1.4.0
CPE:
cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
This vulnerability affects 8 software configuration(s). Ensure you patch all affected systems.

Severity Details

5.5
out of 10.0
Medium

Weakness Type (CWE)

CWE-400

Uncontrolled Resource Consumption

Description
The product does not properly control the allocation and maintenance of a limited resource.
Exploit Likelihood
High
Typical Severity
High
Abstraction Level
Class

Key Information

Published Date
March 23, 2020