Vulnerability in Tika's SQLite3Parser
Issue date: 29-04-2019Affects versions: 13.0, 12.6, 11.2
Issue ID: SECURITY-99
Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Bloomreach Experience Manager prior to 11.2.12, 12.6.2, and 13.0.1, and earlier versions.
Severity
Medium
Description
A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
Instructions
Every customer is strongly advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.