Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.113167
Category:Web application abuses
Title:Apache Tika Server 1.17 Multiple Vulnerabilities
Summary:Apache Tika Server is prone to multiple vulnerabilities,; including Command Execution and Denial of Service
Description:Summary:
Apache Tika Server is prone to multiple vulnerabilities,
including Command Execution and Denial of Service

Vulnerability Insight:
The following vulnerabilities exist:

In Apache Tika, clients could send carefully crafted headers to tika-server that could be used to inject commands
into the command line of the server running tika-server.
This vulnerability only affects those running tika-server on a server that is open to untrusted clients.

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser.

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser.

Vulnerability Impact:
Successful exploitation could allow an attacker to eventually gain full control
over the target system.

Affected Software/OS:
Apache Tika Server through version 1.17.

Solution:
Update to version 1.18.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-1335
BugTraq ID: 104001
http://www.securityfocus.com/bid/104001
https://www.exploit-db.com/exploits/46540/
http://packetstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.html
https://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca@%3Cdev.tika.apache.org%3E
RedHat Security Advisories: RHSA-2019:3140
https://access.redhat.com/errata/RHSA-2019:3140
Common Vulnerability Exposure (CVE) ID: CVE-2018-1338
https://lists.apache.org/thread.html/4d20c5748fb9f836653bc78a1bad991ba8485d82a1e821f70b641932@%3Cdev.tika.apache.org%3E
RedHat Security Advisories: RHSA-2018:2669
https://access.redhat.com/errata/RHSA-2018:2669
Common Vulnerability Exposure (CVE) ID: CVE-2018-1339
https://lists.apache.org/thread.html/4d2cb5c819401bb075e2a1130e0d14f0404a136541a6f91da0225828@%3Cdev.tika.apache.org%3E
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.