CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2021-35517: commons compress from 1.1 (inclusive), through 1.20 (inclusive); +27 more affected products

CVE-2021-35517. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.10614 (percentile 0.95687), scored 2026-10-08.

Affected technology

commons compress · from 1.1 (inclusive), through 1.20 (inclusive)
apache

active iq unified manager · Version not applicable in the source CPE
netapp

oncommand insight · Version not applicable in the source CPE
netapp

banking apis · from 18.1 (inclusive), through 18.3 (inclusive)
oracle

banking apis · 19.1
oracle

banking apis · 19.2
oracle

banking apis · 20.1
oracle

banking apis · 21.1
oracle

banking digital experience · from 18.1 (inclusive), through 18.3 (inclusive)
oracle

banking digital experience · 19.1
oracle

banking digital experience · 19.2
oracle

banking digital experience · 20.1
oracle

banking digital experience · 21.1
oracle

banking enterprise default management · 2.7.0
oracle

banking party management · 2.7.0
oracle

banking payments · 14.5
oracle

banking trade finance · 14.5
oracle

banking treasury management · 14.5
oracle

business process management suite · 12.2.1.3.0
oracle

business process management suite · 12.2.1.4.0
oracle

commerce guided search · 11.3.2
oracle

communications billing and revenue management · 12.0.0.4
oracle

communications cloud native core service communication proxy · 1.14.0
oracle

communications cloud native core unified data repository · 1.14.0
oracle

communications diameter intelligence hub · from 8.0.0 (inclusive), through 8.2.3 (inclusive)
oracle

communications session route manager · from 8.0.0 (inclusive), through 8.2.5 (inclusive)
oracle

financial services crime and compliance management studio · 8.0.8.2.0
oracle

financial services crime and compliance management studio · 8.0.8.3.0
oracle

financial services enterprise case management · 8.0.7.2.0
oracle

financial services enterprise case management · 8.0.8.1.0
oracle

flexcube universal banking · from 14.0.0 (inclusive), through 14.3.0 (inclusive)
oracle

flexcube universal banking · 12.4
oracle

flexcube universal banking · 14.5
oracle

healthcare data repository · 8.1.0
oracle

insurance policy administration · 11.0.2
oracle

insurance policy administration · 11.1.0
oracle

insurance policy administration · 11.2.8
oracle

insurance policy administration · 11.3.0
oracle

insurance policy administration · 11.3.1
oracle

peoplesoft enterprise peopletools · 8.57
oracle

peoplesoft enterprise peopletools · 8.58
oracle

peoplesoft enterprise peopletools · 8.59
oracle

primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle

primavera unifier · 18.8
oracle

primavera unifier · 19.12
oracle

primavera unifier · 20.12
oracle

utilities testing accelerator · 6.0.0.1.1
oracle

utilities testing accelerator · 6.0.0.2.2
oracle

utilities testing accelerator · 6.0.0.3.1
oracle

webcenter portal · 12.2.1.3.0
oracle

webcenter portal · 12.2.1.4.0
oracle

communications messaging server · 8.1
oracle

Apache Commons Compress · 1.1 to before Apache Commons Compress*
Apache Software Foundation

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-130, CWE-770
CCR priority
32.7 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
EPSS
0.10614 · percentile 0.95687 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-35517.html