Medium severity5.5NVD Advisory· Published May 16, 2022· Updated Jun 17, 2026
CVE-2022-25169
CVE-2022-25169
Description
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tika:tikaMaven | < 1.28.2 | 1.28.2 |
org.apache.tika:tikaMaven | >= 2.0.0, < 2.4.0 | 2.4.0 |
Affected products
8cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*range: >=17.7,<=17.12
- cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2022/05/16/4nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-7qcq-xp2f-56f6ghsaADVISORY
- lists.apache.org/thread/t3tb51sf0k2pmbnzsrrrm23z9r1c10rknvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-25169ghsaADVISORY
- security.netapp.com/advisory/ntap-20220804-0004/nvdThird Party Advisory
- www.oracle.com/security-alerts/cpujul2022.htmlnvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20220804-0004ghsaWEB
News mentions
0No linked articles in our index yet.