CVE-2021-23926
published 2021-01-14CVE-2021-23926: The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
6.21%
92.7th percentile
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xmlbeans | <= 2.6.0 | — |
| apache | xmlbeans | >= 0 < 3.0.2-1 | 3.0.2-1 |
| apache | xmlbeans | >= 0 < 3.0.2-1 | 3.0.2-1 |
| apache | xmlbeans | >= 0 < 3.0.2-1 | 3.0.2-1 |
| apache | xmlbeans | >= 0 < 3.0.2-1 | 3.0.2-1 |
| apache_software_foundation | apache_xmlbeans | Apache XMLBeans – 2.6.0 | — |
| debian | debian_linux | — | — |
| debian | xmlbeans | < xmlbeans 3.0.2-1 (bookworm) | xmlbeans 3.0.2-1 (bookworm) |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_oracle9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: Core (Apache XMLBeans) — CVE-2021-23926
vendor_oracle·2026-01-15·CVSS 9.1
CVE-2021-23926 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Core (Apache XMLBeans) — CVE-2021-23926
Oracle Oracle Analytics Risk Matrix: Core (Apache XMLBeans) vulnerability
CVE: CVE-2021-23926
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Analytics Risk Matrix: BI Platform Security (Apache XMLBeans) — CVE-2021-23926
vendor_oracle·2025-01-15·CVSS 9.1
CVE-2021-23926 [CRITICAL] Oracle Oracle Analytics Risk Matrix: BI Platform Security (Apache XMLBeans) — CVE-2021-23926
Oracle Oracle Analytics Risk Matrix: BI Platform Security (Apache XMLBeans) vulnerability
CVE: CVE-2021-23926
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Analytics Risk Matrix: BI FNDN (Apache XMLBeans) — CVE-2021-23926
vendor_oracle·2024-07-15·CVSS 9.1
CVE-2021-23926 [CRITICAL] Oracle Oracle Analytics Risk Matrix: BI FNDN (Apache XMLBeans) — CVE-2021-23926
Oracle Oracle Analytics Risk Matrix: BI FNDN (Apache XMLBeans) vulnerability
CVE: CVE-2021-23926
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Fabric Layer (Apache XMLBeans) — CVE-2021-23926
vendor_oracle·2023-07-15·CVSS 9.1
CVE-2021-23926 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Fabric Layer (Apache XMLBeans) — CVE-2021-23926
Oracle Oracle Fusion Middleware Risk Matrix: Fabric Layer (Apache XMLBeans) vulnerability
CVE: CVE-2021-23926
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Analytics Risk Matrix: Visual Analyzer (Apache POI) — CVE-2021-23926
vendor_oracle·2023-04-15·CVSS 7.3
CVE-2021-23926 [CRITICAL] Oracle Oracle Analytics Risk Matrix: Visual Analyzer (Apache POI) — CVE-2021-23926
Oracle Oracle Analytics Risk Matrix: Visual Analyzer (Apache POI) vulnerability
CVE: CVE-2021-23926
CVSS: 7.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Marketing (XMLBeans) — CVE-2021-23926
vendor_oracle·2022-10-15·CVSS 9.1
CVE-2021-23926 [CRITICAL] Oracle Oracle Siebel CRM Risk Matrix: Marketing (XMLBeans) — CVE-2021-23926
Oracle Oracle Siebel CRM Risk Matrix: Marketing (XMLBeans) vulnerability
CVE: CVE-2021-23926
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Thirdparty Patch (Apache XMLBeans) — CVE-2021-23926
vendor_oracle·2022-07-15·CVSS 9.1
CVE-2021-23926 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Thirdparty Patch (Apache XMLBeans) — CVE-2021-23926
Oracle Oracle Fusion Middleware Risk Matrix: Thirdparty Patch (Apache XMLBeans) vulnerability
CVE: CVE-2021-23926
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: nVision (XMLBeans) — CVE-2021-23926
vendor_oracle·2021-10-15·CVSS 9.1
CVE-2021-23926 [CRITICAL] Oracle Oracle PeopleSoft Risk Matrix: nVision (XMLBeans) — CVE-2021-23926
Oracle Oracle PeopleSoft Risk Matrix: nVision (XMLBeans) vulnerability
CVE: CVE-2021-23926
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
xmlbeans: allowed malicious XML input may lead to XML Entity Expansion attack
vendor_redhat·2021-01-13·CVSS 9.1
CVE-2021-23926 [CRITICAL] CWE-776 xmlbeans: allowed malicious XML input may lead to XML Entity Expansion attack
xmlbeans: allowed malicious XML input may lead to XML Entity Expansion attack
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
A flaw was found when parsing XML files using XMLBeans 2.6.0 or below. The underlying parser created by XMLBeans could be susceptible to XML External Entity (XXE) attacks. The highest threat from this vulnerability is to confidentiality and system availability.
Mitigation: Affected users are advised to update to Apache XMLBeans 3.0.0 or above, which fixes this vulnerability.
Package: xmlbeans (Red Hat BPM Suite 6) - Out of support scope
Package: xmlbeans (Red Hat
Debian
CVE-2021-23926: xmlbeans - The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties ...
vendor_debian·2021·CVSS 9.1
CVE-2021-23926 [CRITICAL] CVE-2021-23926: xmlbeans - The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties ...
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
Scope: local
bookworm: resolved (fixed in 3.0.2-1)
bullseye: resolved (fixed in 3.0.2-1)
forky: resolved (fixed in 3.0.2-1)
sid: resolved (fixed in 3.0.2-1)
trixie: resolved (fixed in 3.0.2-1)
GHSA
Improper Restriction of Recursive Entity References in Apache XMLBeans
ghsa·2021-06-16
CVE-2021-23926 [CRITICAL] CWE-776 Improper Restriction of Recursive Entity References in Apache XMLBeans
Improper Restriction of Recursive Entity References in Apache XMLBeans
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
OSV
Improper Restriction of Recursive Entity References in Apache XMLBeans
osv·2021-06-16
CVE-2021-23926 [CRITICAL] Improper Restriction of Recursive Entity References in Apache XMLBeans
Improper Restriction of Recursive Entity References in Apache XMLBeans
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
OSV
CVE-2021-23926: The XML parsers used by XMLBeans up to version 2
osv·2021-01-14·CVSS 9.1
CVE-2021-23926 [CRITICAL] CVE-2021-23926: The XML parsers used by XMLBeans up to version 2
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, January 2025 Security Update Review
blogs_qualys·2025-01-23
Oracle Critical Patch Update, January 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its first quarterly edition of this year’s Critical Patch Update, which received patches for 318 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 85 constituting about 27% of the total patches released. Oracle MySQL and Oracle Financial Services Applications followed,
Qualys
Oracle Critical Patch Update, January 2025 Security Update Review | Qualys
blogs_qualys·2025-01-23
Oracle Critical Patch Update, January 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its first quarterly edition of this year’s Critical Patch Update, which received patches for 318 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 85 constituting about 27% of the total patches released. Oracle MySQL and Oracle Financial Services Applications fol
https://issues.apache.org/jira/browse/XMLBEANS-517https://lists.apache.org/thread.html/r2dc5588009dc9f0310b7382269f932cc96cae4c3901b747dda1a7fed%40%3Cjava-dev.axis.apache.org%3Ehttps://lists.apache.org/thread.html/rbb01d10512098894cd5f22325588197532c64f1c818ea7e4120d40c1%40%3Cjava-dev.axis.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/06/msg00024.htmlhttps://poi.apache.org/https://security.netapp.com/advisory/ntap-20210513-0004/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://issues.apache.org/jira/browse/XMLBEANS-517https://lists.apache.org/thread.html/r2dc5588009dc9f0310b7382269f932cc96cae4c3901b747dda1a7fed%40%3Cjava-dev.axis.apache.org%3Ehttps://lists.apache.org/thread.html/rbb01d10512098894cd5f22325588197532c64f1c818ea7e4120d40c1%40%3Cjava-dev.axis.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/06/msg00024.htmlhttps://poi.apache.org/https://security.netapp.com/advisory/ntap-20210513-0004/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-01-14
Published