Cyber Resilience

CVE-2021-28657

Medium

Published: 31 March 2021

Published
31 March 2021
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score 0.0022 44.9th percentile
Risk Priority 11 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2021-28657 is a medium-severity Infinite Loop (CWE-835) vulnerability in Oracle Primavera Unifier. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 44.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

apache
tika
≤ 1.25
oracle
healthcare foundation
7.3.0, 8.0.0, 8.1.0
oracle
primavera unifier
18.8, 19.12, 20.12 · 17.7 — 17.12
oracle
webcenter portal
12.2.1.3.0, 12.2.1.4.0
oracle
communications messaging server
8.1

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-835

Enables transfer to alternate site if an infinite loop at the primary renders processing unavailable.

addresses: CWE-835

Detects and mitigates infinite loops that produce sustained resource consumption.

References