An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HApache Portable Runtime
APPApache1.7.0Oracle HTTP Server
APPOracle12.2.1.3.012.2.1.4.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Memory
CWE
Referencje
Powiązane podatności
CVE-2026-21962CRITICAL10.0⚠ KEVPL ✓ten sam produkt
Auth Bypass w Oracle HTTP Server i WebLogic Server Proxy Plug-in (CVSS 10.0)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓ten sam produkt
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2026-60364CRITICAL9.8PL ✓ten sam produkt
Auth Bypass w Oracle WebLogic Server Proxy Plug-In – nieautoryzowana modyfikacja danych
CVE-2026-60363CRITICAL9.8PL ✓ten sam produkt
Krytyczna podatność Auth Bypass w Oracle HTTP Server (Apache Plugin)
CVE-2026-60365CRITICAL10.0PL ✓ten sam produkt
Auth Bypass w Oracle WebLogic Server Proxy Plug-In — pełen dostęp do danych