HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-35940

CVSS 7.1v3.1pub. 2021-08-23upd. 2024-11-21

An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
  • Apache Portable Runtime

    APP
    Apache
    1.7.0
  • Oracle HTTP Server

    APP
    Oracle
    12.2.1.3.012.2.1.4.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-21962CRITICAL10.0⚠ KEVPL ✓same product

Auth Bypass w Oracle HTTP Server i WebLogic Server Proxy Plug-in (CVSS 10.0)

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2026-60364CRITICAL9.8PL ✓same product

Auth Bypass w Oracle WebLogic Server Proxy Plug-In – nieautoryzowana modyfikacja danych

CVE-2026-60363CRITICAL9.8PL ✓same product

Krytyczna podatność Auth Bypass w Oracle HTTP Server (Apache Plugin)

CVE-2026-60365CRITICAL10.0PL ✓same product

Auth Bypass w Oracle WebLogic Server Proxy Plug-In — pełen dostęp do danych