CVE-2020-9489 describes multiple vulnerabilities in Apache Tika's parsers, including OneNote, ICNS, MP3, MP4, SAS7BDAT, and Image parsers. These flaws, affecting products like Apache Tika, Oracle Communications Messaging Server, and Oracle WebCenter Portal, can be triggered by specially crafted or corrupt files. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring user interaction. Successful exploitation could lead to denial of service through System.exit calls, out-of-memory errors, or infinite loops, but does not impact confidentiality or integrity. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with a large percentage of reported vulnerabilities. Users are advised to upgrade to Apache Tika 1.24.1 or later to mitigate these risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.24CPE matchmatch criteria | cpe:2.3:a:apache:tika:1.24:*:*:*:*:*:*:* | ||
12.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* | ||
12.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* | ||
>= 17.7, <= 17.12CPE matchmatch criteria | cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* | ||
16.1CPE matchmatch criteria | cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.