CVE-2023-44483
published 2023-10-20CVE-2023-44483: All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.21%
65.1th percentile
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | santuario_xml_security_for_java | < 2.2.6 | 2.2.6 |
| apache | santuario_xml_security_for_java | >= 2.3.0 < 2.3.4 | 2.3.4 |
| apache | santuario_xml_security_for_java | >= 3.0.0 < 3.0.3 | 3.0.3 |
| apache_software_foundation | apache_santuario | >= 2.2 < 2.2.6 | 2.2.6 |
| apache_software_foundation | apache_santuario | >= 2.3 < 2.3.4 | 2.3.4 |
| apache_software_foundation | apache_santuario | >= 3.0 < 3.0.3 | 3.0.3 |
| debian | libxml-security-java | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Santuario XML Security For Java) — CVE-2023-44483
vendor_oracle·2025-10-15·CVSS 6.5
CVE-2023-44483 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Santuario XML Security For Java) — CVE-2023-44483
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2023-44483
CVSS: 6.5
Protocol: Multiple
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Core (Apache Santuario XML Security For Java) — CVE-2023-44483
vendor_oracle·2025-07-15·CVSS 6.5
CVE-2023-44483 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: Core (Apache Santuario XML Security For Java) — CVE-2023-44483
Oracle Oracle PeopleSoft Risk Matrix: Core (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2023-44483
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Santuario XML Security For Java) — CVE-2023-44483
vendor_oracle·2025-01-15·CVSS 6.5
CVE-2023-44483 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Santuario XML Security For Java) — CVE-2023-44483
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2023-44483
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: PSEM Plugin (Apache Santuario XML Security For Java) — CVE-2023-44483
vendor_oracle·2024-10-15·CVSS 6.5
CVE-2023-44483 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: PSEM Plugin (Apache Santuario XML Security For Java) — CVE-2023-44483
Oracle Oracle Enterprise Manager Risk Matrix: PSEM Plugin (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2023-44483
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Apache Santuario XML Security For Java) — CVE-2023-44483
vendor_oracle·2024-07-15·CVSS 6.5
CVE-2023-44483 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Installer (Apache Santuario XML Security For Java) — CVE-2023-44483
Oracle Oracle Financial Services Applications Risk Matrix: Installer (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2023-44483
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Santuario XML Security For Java) — CVE-2023-44483
vendor_oracle·2024-04-15·CVSS 6.5
CVE-2023-44483 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Santuario XML Security For Java) — CVE-2023-44483
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2023-44483
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Apache Santuario XML Security For Java) — CVE-2023-44483
vendor_oracle·2024-01-15·CVSS 6.5
CVE-2023-44483 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Apache Santuario XML Security For Java) — CVE-2023-44483
Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2023-44483
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
santuario: Private Key disclosure in debug-log output
vendor_redhat·2023-10-20·CVSS 6.5
CVE-2023-44483 [MEDIUM] CWE-532 santuario: Private Key disclosure in debug-log output
santuario: Private Key disclosure in debug-log output
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: santuario (Red Hat build of Apache Camel for Spring Boot 3) - Affected
Package: santuario (Red Hat build of Apicurio Registry 2) - Not affected
Package: santuario (Red Hat Data Grid 8) - Not affected
Package: santuario (Red Hat Fuse 7) - Out of support scope
Pack
Debian
CVE-2023-44483: libxml-security-java - All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, ...
vendor_debian·2023·CVSS 6.5
CVE-2023-44483 [MEDIUM] CVE-2023-44483: libxml-security-java - All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, ...
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
ghsa·2023-10-20
CVE-2023-44483 [MEDIUM] CWE-532 Apache Santuario - XML Security for Java are vulnerable to private key disclosure
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
OSV
CVE-2023-44483: All versions of Apache Santuario - XML Security for Java prior to 2
osv·2023-10-20·CVSS 6.5
CVE-2023-44483 [MEDIUM] CVE-2023-44483: All versions of Apache Santuario - XML Security for Java prior to 2
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
OSV
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
osv·2023-10-20
CVE-2023-44483 [MEDIUM] Apache Santuario - XML Security for Java are vulnerable to private key disclosure
Apache Santuario - XML Security for Java are vulnerable to private key disclosure
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
No detection rules found.
No public exploits indexed.
2023-10-20
Published