In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "14.0"
},
{
"last_affected": "14.3"
}
],
"cpes": [
"cpe:2.3:a:oracle:flexcube_universal_banking:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:flexcube_universal_banking",
"source": "CPE_RANGE"
},
{
"extracted_events": [
{
"last_affected": "14.5"
}
],
"cpes": [
"cpe:2.3:a:oracle:banking_payments:14.5:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_payments",
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "14.5"
}
],
"cpes": [
"cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_trade_finance_process_management",
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "14.5"
}
],
"cpes": [
"cpe:2.3:a:oracle:banking_treasury_management:14.5:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_treasury_management",
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "1.9.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_cloud_native_core_console",
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "18.0"
},
{
"last_affected": "19.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:customer_management_and_segmentation_foundation",
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "14.5"
}
],
"cpes": [
"cpe:2.3:a:oracle:flexcube_universal_banking:14.5:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:flexcube_universal_banking",
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
},
{
"last_affected": "14.1.1.0.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:fusion_middleware_common_libraries_and_tools:14.1.1.0.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:fusion_middleware_common_libraries_and_tools",
"source": "CPE_STRING"
},
{
"extracted_events": [
{
"last_affected": "2.12.42"
}
],
"cpes": [
"cpe:2.3:a:oracle:oss_support_tools:2.12.42:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:oss_support_tools",
"source": "CPE_STRING"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.0.22"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.5"
}
],
"cpe": "cpe:2.3:a:apache:mina:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE"
}