SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-27568

When it is not caught, it may cause programs using the library to crash or expose sensitive information.

MEDIUM 5.9EPSS 2.91%

Does this matter?

Lower severity and a low EPSS score (2.91%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
2.91% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-754
Affected
json-smart project/json-smart-v1 · json-smart project/json-smart-v2 · oracle/communications cloud native core policy · oracle/oss support tools · oracle/peoplesoft enterprise peopletools · oracle/utilities framework · oracle/weblogic server
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.