CVE-2020-1945: Apache Ant

Medium severity, CVSS 6.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

Affected products

  • Apache Ant: from 1.1, up to and including 1.9.14; from 1.10.0, up to and including 1.10.7
  • Canonical Ubuntu Linux: version 19.10 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Opensuse Leap: version 15.2 only
  • Oracle Agile Engineering Data Management: version 6.2.1.0 only
  • Oracle Banking Enterprise Collections: from 2.7.0, up to and including 2.9.0
  • Oracle Banking Liquidity Management: from 14.0.0, up to and including 14.4.0
  • Oracle Banking Platform: from 2.4.0, up to and including 2.9.0
  • Oracle Business Process Management Suite: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Category Management Planning & Optimization: version 15.0.3 only
  • Oracle Communications Asap: version 7.3 only
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
  • Oracle Communications Metasolv Solution: version 6.3.0 only
  • Oracle Communications Order And Service Management: version 7.3 only; version 7.4 only
  • Oracle Data Integrator: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Endeca Information Discovery Studio: version 3.2.0 only
  • Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
  • Oracle Enterprise Repository: version 11.1.1.7.0 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.1.0
  • Oracle Flexcube Investor Servicing: version 12.1.0 only; version 12.3.0 only; version 12.4.0 only; version 14.0.0 only; version 14.1.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Health Sciences Information Manager: from 3.0, up to and including 3.0.2
  • Oracle Primavera Gateway: from 16.2.0, up to and including 16.2.11; from 17.12.0, up to and including 17.12.7
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only; version 19.12 only
  • Oracle Rapid Planning: version 12.1 only; version 12.2 only
  • and 25 more

Published 2020-05-14. Last modified 2026-06-17.