GHSA-4pv3-63jw-4jw2 · Severity: medium · Ecosystem: maven — Missing Release of Memory after Effective Lifetime in Apache Tika
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.
Conclusion & alert: CVE-2020-9489 is rated Moderate Risk (53/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.55%). Core evidence: EPSS rose +1.96% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.59% | 2.55% | +1.96% |
| 2 | 2026-06-12 | 0.39% | 0.59% | +0.21% |
| 3 | 2025-11-21 | — | 0.39% | — |
Full EPSS history (23 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-4pv3-63jw-4jw2 · Severity: medium · Ecosystem: maven — Missing Release of Memory after Effective Lifetime in Apache Tika
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-9489 not yet assigned priority: Debian including 1 source packages (tika), 2 status rows across 2 suites (bullseye, sid): open 2. | https://security-tracker.debian.org/tracker/CVE-2020-9489 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-9489 |
suse
|
medium | CVE-2020-9489 severity moderate: SUSE including 1 source package names (tika-core), 2 product×package rows across 2 product lines (SUSE Manager Server 3.2, SUSE Manager Server Module 4.0): Known Not Affected 2. | https://www.suse.com/security/cve/CVE-2020-9489/ |
ubuntu
|
medium | CVE-2020-9489 medium priority: Ubuntu including 1 source packages (tika), 17 status rows across 17 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 7, not-affected 7, needs-triage 2, DNE 1. | https://ubuntu.com/security/CVE-2020-9489 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | tika | 1.24 | cpe:2.3:a:apache:tika:1.24:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.0.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:* |
| oracle | flexcube_private_banking | 12.1.0 | cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:* |
| oracle | primavera_unifier | >= 17.7, <= 17.12 | cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 16.1 | cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 16.2 | cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 18.8 | cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:* |
| oracle | primavera_unifier | 19.12 | cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:* |
| oracle | webcenter_portal | 12.2.1.3.0 | cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | webcenter_portal | 12.2.1.4.0 | cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | communications_messaging_server | 8.1 | cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b%40%3Cnotifications.james.apache.org%3E | |
| https://lists.apache.org/thread.html/r4d943777e36ca3aa6305a45da5acccc54ad894f2d5a07186cfa2442c%40%3Cdev.tika.apache.org%3E | Mailing List Vendor Advisory |
| https://www.oracle.com//security-alerts/cpujul2021.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuApr2021.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Patch Third Party Advisory |