← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-1945

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

No Active Exploit Signals
CVSS Base Score
6.3
MEDIUM
EPSS Probability:1.79%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
apache ant all
canonical ubuntu_linux 19.10
fedoraproject fedora 31, 32
opensuse leap 15.2
oracle agile_engineering_data_management 6.2.1.0
oracle banking_enterprise_collections all
oracle banking_liquidity_management all
oracle banking_platform all
oracle business_process_management_suite 12.2.1.3.0, 12.2.1.4.0
oracle category_management_planning_\&_optimization 15.0.3
oracle communications_asap 7.3
oracle communications_diameter_signaling_router all
oracle communications_metasolv_solution 6.3.0
oracle communications_order_and_service_management 7.3, 7.4
oracle data_integrator 12.2.1.3.0, 12.2.1.4.0
oracle endeca_information_discovery_studio 3.2.0
oracle enterprise_manager_ops_center 12.4.0.0
oracle enterprise_repository 11.1.1.7.0
oracle financial_services_analytical_applications_infrastructure all
oracle flexcube_investor_servicing 12.1.0, 12.3.0, 12.4.0, 14.0.0, 14.1.0
oracle flexcube_private_banking 12.0.0, 12.1.0
oracle health_sciences_information_manager all
oracle primavera_gateway all
oracle primavera_unifier 16.1, 16.2, 18.8, 19.12
oracle rapid_planning 12.1, 12.2
oracle real-time_decision_server 3.2.1.0
oracle retail_advanced_inventory_planning 14.1, 15.0, 16.0
oracle retail_assortment_planning 15.0.3, 16.0.3
oracle retail_back_office 14.0, 14.1
oracle retail_bulk_data_integration 15.0, 16.0, 16.0.3.0, 19.0.1
oracle retail_central_office 14.0, 14.1
oracle retail_data_extractor_for_merchandising 1.9, 1.10
oracle retail_extract_transform_and_load 13.2.5, 13.2.8
oracle retail_financial_integration 14.1.3.2, 15.0, 15.0.4.0, 16.0, 16.0.3.0
oracle retail_integration_bus 14.1, 14.1.3.2, 15.0, 15.0.4.0, 16.0, 16.0.3.0, 19.0.1.0
oracle retail_item_planning 15.0.3
oracle retail_macro_space_optimization 15.0.3
oracle retail_merchandise_financial_planning 15.0.3
oracle retail_merchandising_system 19.0.1
oracle retail_point-of-service 14.0, 14.1, 15.0, 16.0
oracle retail_predictive_application_server 14.0.3, 14.1.3, 15.0.3, 16.0.3, 16.0.3.0
oracle retail_regular_price_optimization 15.0.3, 16.0.3
oracle retail_replenishment_optimization 15.0.3
oracle retail_returns_management 14.0, 14.1
oracle retail_service_backbone 14.1.3.2, 15.0, 15.0.4.0, 16.0, 16.0.3.0, 19.0.1.0
oracle retail_size_profile_optimization 15.0.3, 16.0.3
oracle retail_store_inventory_management 14.0.4, 14.1, 14.1.3, 15.0, 15.0.3, 16.0, 16.0.3
oracle retail_xstore_point_of_service 15.0.4, 16.0.6, 17.0.4, 18.0.3, 19.0.2
oracle timesten_in-memory_database 11.2.2.8.49
oracle utilities_framework 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.4.0.0.0, 4.4.0.2.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.793%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2019-12-02T00:00:00
Published2020-05-14T15:57:34
Last Updated2024-08-04T06:54:00

LINK COPIED TO CLIPBOARD