CVE-2021-40690
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Affected (34)
Products: Apache: Santuario Xml Security For Java, Cxf, Tomee · Debian: Debian Linux · Oracle: Agile Plm, Commerce Guided Search, Commerce Platform, Communications Diameter Intelligence Hub, Communications Messaging Server, Flexcube Private Banking, Outside In Technology, Peoplesoft Enterprise Peopletools, Retail Bulk Data Integration, Retail Financial Integration, Retail Integration Bus, Retail Merchandising System, Retail Service Backbone, Weblogic Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1.7 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.3.6 | |
| Version 11.3.2 | |
| Version 11.3.2 | |
| From 8.0.0 to 8.1.0 | |
| Version 8.1 | |
| Version 12.1.0 | |
| Version 8.5.5 | |
| Version 8.58 | |
| Version 16.0.3 | |
| Version 14.1.3.2 | |
| Version 14.1.3.2 | |
| Version 16.0.3 | |
| Version 14.1.3.2 | |
| Version 12.2.1.4.0 |
References (28)
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Issue TrackingMailing ListPatchThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.