Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2021-40690

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
apache / tomee - 8.0.8
apache / cxf 3.4.4 3.4.4.x
debian / debian_linux 9.0 9.0.x
debian / debian_linux 10.0 10.0.x
debian / debian_linux 11.0 11.0.x
oracle / flexcube_private_banking 12.1.0 12.1.0.x
oracle / agile_plm 9.3.6 9.3.6.x
oracle / weblogic_server 12.2.1.4.0 12.2.1.4.0.x
oracle / peoplesoft_enterprise_peopletools 8.58 8.58.x
oracle / outside_in_technology 8.5.5 8.5.5.x
oracle / weblogic_server 14.1.1.0.0 14.1.1.0.0.x
oracle / retail_merchandising_system 16.0.3 16.0.3.x
oracle / retail_service_backbone 16.0.3 16.0.3.x
oracle / retail_financial_integration 16.0.3 16.0.3.x
oracle / retail_integration_bus 16.0.3 16.0.3.x
oracle / commerce_guided_search 11.3.2 11.3.2.x
oracle / peoplesoft_enterprise_peopletools 8.59 8.59.x
oracle / retail_service_backbone 15.0.3.1 15.0.3.1.x
oracle / retail_service_backbone 14.1.3.2 14.1.3.2.x
oracle / communications_messaging_server 8.1 8.1.x
oracle / retail_merchandising_system 19.0.1 19.0.1.x
oracle / retail_integration_bus 14.1.3.2 14.1.3.2.x
oracle / retail_financial_integration 14.1.3.2 14.1.3.2.x
oracle / retail_integration_bus 15.0.3.1 15.0.3.1.x
oracle / retail_financial_integration 15.0.3.1 15.0.3.1.x
oracle / commerce_platform 11.3.2 11.3.2.x
oracle / retail_service_backbone 19.0.1 19.0.1.x
oracle / retail_integration_bus 19.0.1 19.0.1.x
oracle / retail_financial_integration 19.0.1 19.0.1.x
oracle / communications_diameter_intelligence_hub 8.0.0 8.1.0.x
oracle / communications_diameter_intelligence_hub 8.2.0 8.2.3.x
oracle / retail_bulk_data_integration 16.0.3 16.0.3.x
org.apache.santuario / xmlsec 2.2.0 2.2.3
org.apache.santuario / xmlsec - 2.1.7
apache / santuario_xml_security_for_java - 2.1.7
apache / santuario_xml_security_for_java 2.2.0 2.2.3