CVE-2021-40690
19.09.2021, 18:15
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.Enginsight
Vendor | Product | Version |
---|---|---|
apache | santuario_xml_security_for_java | 𝑥 < 2.1.7 |
apache | santuario_xml_security_for_java | 2.2.0 ≤ 𝑥 < 2.2.3 |
apache | cxf | 3.4.4 |
apache | tomee | 𝑥 < 8.0.8 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
oracle | agile_plm | 9.3.6 |
oracle | commerce_guided_search | 11.3.2 |
oracle | commerce_platform | 11.3.2 |
oracle | communications_diameter_intelligence_hub | 8.0.0 ≤ 𝑥 ≤ 8.1.0 |
oracle | communications_diameter_intelligence_hub | 8.2.0 ≤ 𝑥 ≤ 8.2.3 |
oracle | communications_messaging_server | 8.1 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | outside_in_technology | 8.5.5 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | peoplesoft_enterprise_peopletools | 8.59 |
oracle | retail_bulk_data_integration | 16.0.3 |
oracle | retail_financial_integration | 14.1.3.2 |
oracle | retail_financial_integration | 15.0.3.1 |
oracle | retail_financial_integration | 16.0.3 |
oracle | retail_financial_integration | 19.0.1 |
oracle | retail_integration_bus | 14.1.3.2 |
oracle | retail_integration_bus | 15.0.3.1 |
oracle | retail_integration_bus | 16.0.3 |
oracle | retail_integration_bus | 19.0.1 |
oracle | retail_merchandising_system | 16.0.3 |
oracle | retail_merchandising_system | 19.0.1 |
oracle | retail_service_backbone | 14.1.3.2 |
oracle | retail_service_backbone | 15.0.3.1 |
oracle | retail_service_backbone | 16.0.3 |
oracle | retail_service_backbone | 19.0.1 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References