cbcvebase.
CVE-2021-23926
published 2021-01-14

CVE-2021-23926: The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include…

PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
6.21%
92.7th percentile
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Affected

13 ranges
VendorProductVersion rangeFixed in
apachexmlbeans<= 2.6.0
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apache_software_foundationapache_xmlbeansApache XMLBeans – 2.6.0
debiandebian_linux
debianxmlbeans< xmlbeans 3.0.2-1 (bookworm)xmlbeans 3.0.2-1 (bookworm)
oraclemiddleware_common_libraries_and_tools
oraclemiddleware_common_libraries_and_tools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_oracle9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.