CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2021-36090: commons compress from 1.0 (inclusive), before 1.21 (exclusive); +34 more affected products

CVE-2021-36090. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.12945 (percentile 0.96228), scored 2026-10-08.

Affected technology

commons compress · from 1.0 (inclusive), before 1.21 (exclusive)
apache

banking apis · from 18.1 (inclusive), through 18.3 (inclusive)
oracle

banking apis · 19.1
oracle

banking apis · 19.2
oracle

banking apis · 20.1
oracle

banking apis · 21.1
oracle

banking digital experience · from 18.1 (inclusive), through 18.3 (inclusive)
oracle

banking digital experience · 19.1
oracle

banking digital experience · 19.2
oracle

banking digital experience · 20.1
oracle

banking digital experience · 21.1
oracle

banking enterprise default management · 2.7.0
oracle

banking party management · 2.7.0
oracle

banking payments · 14.5
oracle

banking platform · 2.6.2
oracle

banking platform · 2.7.1
oracle

banking platform · 2.9.0
oracle

banking platform · 2.12.0
oracle

banking trade finance · 14.5
oracle

banking treasury management · 14.5
oracle

business process management suite · 12.2.1.3.0
oracle

business process management suite · 12.2.1.4.0
oracle

commerce guided search · 11.3.2
oracle

communications billing and revenue management · 12.0.0.4
oracle

communications cloud native core automated test suite · 1.8.0
oracle

communications cloud native core service communication proxy · 1.14.0
oracle

communications cloud native core unified data repository · 1.14.0
oracle

communications diameter intelligence hub · from 8.0.0 (inclusive), through 8.2.3 (inclusive)
oracle

communications diameter intelligence hub · 8.2.3
oracle

communications element manager · from 8.2.0 (inclusive), through 8.2.4.0 (inclusive)
oracle

communications session report manager · from 8.2.0 (inclusive), through 8.2.5.0 (inclusive)
oracle

communications session route manager · from 8.0.0 (inclusive), through 8.2.5.0 (inclusive)
oracle

communications unified inventory management · 7.4.0
oracle

communications unified inventory management · 7.4.1
oracle

communications unified inventory management · 7.4.2
oracle

communications unified inventory management · 7.5.0
oracle

financial services analytical applications infrastructure · from 8.0.6 (inclusive), through 8.1.1 (inclusive)
oracle

financial services crime and compliance management studio · 8.0.8.2.0
oracle

financial services crime and compliance management studio · 8.0.8.3.0
oracle

financial services enterprise case management · Exact affected versions not specified by the source
oracle

financial services enterprise case management · 8.0.7.2.0
oracle

financial services enterprise case management · 8.0.8.1.0
oracle

flexcube universal banking · from 14.0.0 (inclusive), through 14.3.0 (inclusive)
oracle

flexcube universal banking · 12.4
oracle

flexcube universal banking · 14.5
oracle

healthcare data repository · 8.1.0
oracle

insurance policy administration · 11.0.2
oracle

insurance policy administration · 11.1.0
oracle

insurance policy administration · 11.2.8
oracle

insurance policy administration · 11.3.0
oracle

insurance policy administration · 11.3.1
oracle

peoplesoft enterprise peopletools · 8.57
oracle

peoplesoft enterprise peopletools · 8.58
oracle

peoplesoft enterprise peopletools · 8.59
oracle

primavera gateway · from 17.12.0 (inclusive), through 17.12.11 (inclusive)
oracle

primavera gateway · from 18.8.0 (inclusive), through 18.8.12 (inclusive)
oracle

primavera gateway · from 19.12.0 (inclusive), through 19.12.11 (inclusive)
oracle

primavera gateway · from 20.12.0 (inclusive), through 20.12.7 (inclusive)
oracle

primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle

primavera unifier · 18.8
oracle

primavera unifier · 19.12
oracle

primavera unifier · 20.12
oracle

utilities testing accelerator · 6.0.0.1.1
oracle

utilities testing accelerator · 6.0.0.2.2
oracle

utilities testing accelerator · 6.0.0.3.1
oracle

webcenter portal · 12.2.1.3.0
oracle

webcenter portal · 12.2.1.4.0
oracle

communications messaging server · 8.1
oracle

active iq unified manager · Version not applicable in the source CPE
netapp

oncommand insight · Version not applicable in the source CPE
netapp

Apache Commons Compress · Apache Commons Compress through 1.20
Apache Software Foundation

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-130
CCR priority
33.2 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
EPSS
0.12945 · percentile 0.96228 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-36090.html