CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apache 1Santuario Xml Security For Java Jun 17, 2026 Oct 20, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML S...Show more |
3Apache DebianOracle18Agile Plm Commerce Guided SearchCommerce Platform+15 moreJun 17, 2026 Sep 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference e...Show more |
3Apache OracleRedhat3Jboss Enterprise Application Platform Santuario Xml Security For JavaWeblogic ServerJun 17, 2026 Aug 23, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a m...Show more |
1Apache 1Santuario Xml Security For Java May 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document. |
1Apache 1Santuario Xml Security For Java Apr 29, 2026 Jan 11, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures...Show more |
1Apache 1Santuario Xml Security For Java Apr 29, 2026 Aug 20, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the Canon...Show more |