Get real-time updates on Telegram
CVE-2021-35517: commons compress from 1.1 (inclusive), through 1.20 (inclusive); +27 more affected products
CVE-2021-35517. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.10614 (percentile 0.95687), scored 2026-10-08.
Affected technology
commons compress · from 1.1 (inclusive), through 1.20 (inclusive)
apache
active iq unified manager · Version not applicable in the source CPE
netapp
oncommand insight · Version not applicable in the source CPE
netapp
banking apis · from 18.1 (inclusive), through 18.3 (inclusive)
oracle
banking apis · 19.1
oracle
banking apis · 19.2
oracle
banking apis · 20.1
oracle
banking apis · 21.1
oracle
banking digital experience · from 18.1 (inclusive), through 18.3 (inclusive)
oracle
banking digital experience · 19.1
oracle
banking digital experience · 19.2
oracle
banking digital experience · 20.1
oracle
banking digital experience · 21.1
oracle
banking enterprise default management · 2.7.0
oracle
banking party management · 2.7.0
oracle
banking payments · 14.5
oracle
banking trade finance · 14.5
oracle
banking treasury management · 14.5
oracle
business process management suite · 12.2.1.3.0
oracle
business process management suite · 12.2.1.4.0
oracle
commerce guided search · 11.3.2
oracle
communications billing and revenue management · 12.0.0.4
oracle
communications cloud native core service communication proxy · 1.14.0
oracle
communications cloud native core unified data repository · 1.14.0
oracle
communications diameter intelligence hub · from 8.0.0 (inclusive), through 8.2.3 (inclusive)
oracle
communications session route manager · from 8.0.0 (inclusive), through 8.2.5 (inclusive)
oracle
financial services crime and compliance management studio · 8.0.8.2.0
oracle
financial services crime and compliance management studio · 8.0.8.3.0
oracle
financial services enterprise case management · 8.0.7.2.0
oracle
financial services enterprise case management · 8.0.8.1.0
oracle
flexcube universal banking · from 14.0.0 (inclusive), through 14.3.0 (inclusive)
oracle
flexcube universal banking · 12.4
oracle
flexcube universal banking · 14.5
oracle
healthcare data repository · 8.1.0
oracle
insurance policy administration · 11.0.2
oracle
insurance policy administration · 11.1.0
oracle
insurance policy administration · 11.2.8
oracle
insurance policy administration · 11.3.0
oracle
insurance policy administration · 11.3.1
oracle
peoplesoft enterprise peopletools · 8.57
oracle
peoplesoft enterprise peopletools · 8.58
oracle
peoplesoft enterprise peopletools · 8.59
oracle
primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle
primavera unifier · 18.8
oracle
primavera unifier · 19.12
oracle
primavera unifier · 20.12
oracle
utilities testing accelerator · 6.0.0.1.1
oracle
utilities testing accelerator · 6.0.0.2.2
oracle
utilities testing accelerator · 6.0.0.3.1
oracle
webcenter portal · 12.2.1.3.0
oracle
webcenter portal · 12.2.1.4.0
oracle
communications messaging server · 8.1
oracle
Apache Commons Compress · 1.1 to before Apache Commons Compress*
Apache Software Foundation
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-130, CWE-770
- CCR priority
- 32.7 /100 (P4)
- CVSS 3.1
- 7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
- EPSS
- 0.10614 · percentile 0.95687 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2021-35517.html