CVE-2022-25169

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/05/2022
Last modified:
09/11/2022

Description

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* 1.28.2 (excluding)
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* 2.0.0 (including) 2.4.0 (excluding)
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* 17.7 (including) 17.12 (including)
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*