CVE-2019-12402: Apache Commons Compress
High severity, CVSS 7.5. EPSS: 16.2% chance of exploitation in the next 30 days.
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
Affected products
- Apache Commons Compress: from 1.15, up to and including 1.18
- Fedoraproject Fedora: version 30 only; version 31 only
- Oracle Banking Payments: from 14.1.0, up to and including 14.4.0
- Oracle Banking Platform: version 2.6.2 only; version 2.7.0 only; version 2.8.0 only; version 2.9.0 only
- Oracle Communications Element Manager: from 8.2.0, up to and including 8.2.2
- Oracle Communications IP Service Activator: version 7.3.0 only; version 7.4.0 only
- Oracle Communications Session Report Manager: from 8.2.0, up to and including 8.2.2
- Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2
- Oracle Customer Management And Segmentation Foundation: version 18.0 only
- Oracle Essbase: version 21.2 only
- Oracle Flexcube Investor Servicing: version 12.1.0 only; version 12.3.0 only; version 12.4.0 only; version 14.0.0 only; version 14.1.0 only
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
- Oracle Hyperion Infrastructure Technology: version 11.1.2.4 only
- Oracle Jdeveloper: version 12.2.1.4.0 only
- Oracle PeopleSoft Enterprise Pt PeopleTools: version 8.56 only; version 8.57 only; version 8.58 only
- Oracle Primavera Gateway: from 18.8.0, up to and including 18.8.8; version 19.12.0 only
- Oracle Retail Integration Bus: version 15.0 only; version 16.0 only
- Oracle Retail Xstore Point Of Service: version 15.0 only; version 16.0 only; version 17.0 only; version 18.0 only; version 19.0 only
- Oracle Webcenter Portal: version 12.2.1.3.0 only; version 12.2.1.4.0 only
Published 2019-08-30. Last modified 2026-06-17.