cbcvebase.
CVE-2021-40690
published 2021-09-19

CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
apachecxf
apachesantuario_xml_security_for_java< 2.1.72.1.7
apachesantuario_xml_security_for_java>= 2.2.0 < 2.2.32.2.3
apachetomee< 8.0.88.0.8
apache_software_foundationapache_santuario>= XML Security for Java < 2.2.3,2.1.72.2.3,2.1.7
atlassiancrowd
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlibxml-security-java< libxml-security-java 2.1.7-1 (bookworm)libxml-security-java 2.1.7-1 (bookworm)
oracleagile_plm
oraclecommerce_guided_search
oraclecommerce_platform
oraclecommunications_diameter_intelligence_hub8.0.0 – 8.1.0
oraclecommunications_diameter_intelligence_hub8.2.0 – 8.2.3
oraclecommunications_messaging_server
oracleflexcube_private_banking
oracleoutside_in_technology
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oracleretail_bulk_data_integration
oracleretail_financial_integration
oracleretail_financial_integration
oracleretail_financial_integration
oracleretail_financial_integration

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH