CVE-2021-42575
published 2021-10-18CVE-2021-42575: The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.84%
85.2th percentile
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | 17.7 – 17.12 | — |
| owasp | java_html_sanitizer | < 20211018.2 | 20211018.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Web Client (Java HTML Sanitizer) — CVE-2021-42575
vendor_oracle·2025-07-15·CVSS 6.1
CVE-2021-42575 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Web Client (Java HTML Sanitizer) — CVE-2021-42575
Oracle Oracle Supply Chain Risk Matrix: Web Client (Java HTML Sanitizer) vulnerability
CVE: CVE-2021-42575
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Hyperion Risk Matrix: Hub (Java HTML Sanitizer) — CVE-2021-42575
vendor_oracle·2024-01-15·CVSS 9.8
CVE-2021-42575 [CRITICAL] Oracle Oracle Hyperion Risk Matrix: Hub (Java HTML Sanitizer) — CVE-2021-42575
Oracle Oracle Hyperion Risk Matrix: Hub (Java HTML Sanitizer) vulnerability
CVE: CVE-2021-42575
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Configuration (Java HTML Sanitizer) — CVE-2021-42575
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2021-42575 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Configuration (Java HTML Sanitizer) — CVE-2021-42575
Oracle Oracle Communications Applications Risk Matrix: Configuration (Java HTML Sanitizer) vulnerability
CVE: CVE-2021-42575
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Platform (OWASP Java HTML Sanitizer ) — CVE-2021-42575
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2021-42575 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Platform (OWASP Java HTML Sanitizer ) — CVE-2021-42575
Oracle Oracle Commerce Risk Matrix: Platform (OWASP Java HTML Sanitizer ) vulnerability
CVE: CVE-2021-42575
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (AntiSamy) — CVE-2021-42575
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2021-42575 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (AntiSamy) — CVE-2021-42575
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (AntiSamy) vulnerability
CVE: CVE-2021-42575
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Platform, Data Persistence (OWASP Java HTML Sanitizer) — CVE-2021-42575
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2021-42575 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Platform, Data Persistence (OWASP Java HTML Sanitizer) — CVE-2021-42575
Oracle Oracle Construction and Engineering Risk Matrix: Platform, Data Persistence (OWASP Java HTML Sanitizer) vulnerability
CVE: CVE-2021-42575
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
owasp-java-html-sanitizer: improper policies enforcement may lead to remote code execution
vendor_redhat·2021-10-18·CVSS 9.8
CVE-2021-42575 [CRITICAL] CWE-20 owasp-java-html-sanitizer: improper policies enforcement may lead to remote code execution
owasp-java-html-sanitizer: improper policies enforcement may lead to remote code execution
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
GHSA
Policies not properly enforced in OWASP Java HTML Sanitizer
ghsa·2021-10-19
CVE-2021-42575 [CRITICAL] CWE-20 Policies not properly enforced in OWASP Java HTML Sanitizer
Policies not properly enforced in OWASP Java HTML Sanitizer
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the `SELECT`, `STYLE`, and `OPTION` elements.
OSV
Policies not properly enforced in OWASP Java HTML Sanitizer
osv·2021-10-19
CVE-2021-42575 [CRITICAL] Policies not properly enforced in OWASP Java HTML Sanitizer
Policies not properly enforced in OWASP Java HTML Sanitizer
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the `SELECT`, `STYLE`, and `OPTION` elements.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed, with
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followe
Qualys
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
blogs_qualys·2023-04-19
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Mi
Qualys
Oracle Patch Tuesday April 2023 Security Update Review
blogs_qualys·2023-04-19
Oracle Patch Tuesday April 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Middlewar
Bugzilla
CVE-2021-42575 owasp-java-html-sanitizer: improper policies enforcement may lead to remote code execution
bugzilla·2021-11-29·CVSS 9.8
CVE-2021-42575 [CRITICAL] CVE-2021-42575 owasp-java-html-sanitizer: improper policies enforcement may lead to remote code execution
CVE-2021-42575 owasp-java-html-sanitizer: improper policies enforcement may lead to remote code execution
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
External Reference:
https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/
https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-10-18
Published