cbcvebase.
CVE-2021-23926
published 2021-01-14

CVE-2021-23926: The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Affected

13 ranges
VendorProductVersion rangeFixed in
apachexmlbeans<= 2.6.0
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apachexmlbeans>= 0 < 3.0.2-13.0.2-1
apache_software_foundationapache_xmlbeansApache XMLBeans – 2.6.0
debiandebian_linux
debianxmlbeans< xmlbeans 3.0.2-1 (bookworm)xmlbeans 3.0.2-1 (bookworm)
oraclemiddleware_common_libraries_and_tools
oraclemiddleware_common_libraries_and_tools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL