CVE-2021-40690
Bypass of the secureValidation property
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Todas las versiones de Apache Santuario - XML Security for Java anteriores a 2.2.3 y 2.1.7 son vulnerables a un problema donde la propiedad "secureValidation" no es pasada correctamente cuando es creado un KeyInfo a partir de un elemento KeyInfoReference. Esto permite a un atacante abusar de una transformación XPath para extraer cualquier archivo local .xml en un elemento RetrievalMethod
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-08 CVE Reserved
- 2021-09-19 CVE Published
- 2024-06-04 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (16)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2021/dsa-5010 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2021-40690 | 2022-09-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2011190 | 2022-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Santuario Xml Security For Java Search vendor "Apache" for product "Santuario Xml Security For Java" | < 2.1.7 Search vendor "Apache" for product "Santuario Xml Security For Java" and version " < 2.1.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Santuario Xml Security For Java Search vendor "Apache" for product "Santuario Xml Security For Java" | >= 2.2.0 < 2.2.3 Search vendor "Apache" for product "Santuario Xml Security For Java" and version " >= 2.2.0 < 2.2.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cxf Search vendor "Apache" for product "Cxf" | 3.4.4 Search vendor "Apache" for product "Cxf" and version "3.4.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomee Search vendor "Apache" for product "Tomee" | < 8.0.8 Search vendor "Apache" for product "Tomee" and version " < 8.0.8" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Plm Search vendor "Oracle" for product "Agile Plm" | 9.3.6 Search vendor "Oracle" for product "Agile Plm" and version "9.3.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Commerce Guided Search Search vendor "Oracle" for product "Commerce Guided Search" | 11.3.2 Search vendor "Oracle" for product "Commerce Guided Search" and version "11.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Commerce Platform Search vendor "Oracle" for product "Commerce Platform" | 11.3.2 Search vendor "Oracle" for product "Commerce Platform" and version "11.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Intelligence Hub Search vendor "Oracle" for product "Communications Diameter Intelligence Hub" | >= 8.0.0 <= 8.1.0 Search vendor "Oracle" for product "Communications Diameter Intelligence Hub" and version " >= 8.0.0 <= 8.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Intelligence Hub Search vendor "Oracle" for product "Communications Diameter Intelligence Hub" | >= 8.2.0 <= 8.2.3 Search vendor "Oracle" for product "Communications Diameter Intelligence Hub" and version " >= 8.2.0 <= 8.2.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Messaging Server Search vendor "Oracle" for product "Communications Messaging Server" | 8.1 Search vendor "Oracle" for product "Communications Messaging Server" and version "8.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.1.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Outside In Technology Search vendor "Oracle" for product "Outside In Technology" | 8.5.5 Search vendor "Oracle" for product "Outside In Technology" and version "8.5.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.58 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.58" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Peopletools Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" | 8.59 Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.59" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Bulk Data Integration Search vendor "Oracle" for product "Retail Bulk Data Integration" | 16.0.3 Search vendor "Oracle" for product "Retail Bulk Data Integration" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 14.1.3.2 Search vendor "Oracle" for product "Retail Financial Integration" and version "14.1.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 15.0.3.1 Search vendor "Oracle" for product "Retail Financial Integration" and version "15.0.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 16.0.3 Search vendor "Oracle" for product "Retail Financial Integration" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 19.0.1 Search vendor "Oracle" for product "Retail Financial Integration" and version "19.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 14.1.3.2 Search vendor "Oracle" for product "Retail Integration Bus" and version "14.1.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 15.0.3.1 Search vendor "Oracle" for product "Retail Integration Bus" and version "15.0.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 16.0.3 Search vendor "Oracle" for product "Retail Integration Bus" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Integration Bus Search vendor "Oracle" for product "Retail Integration Bus" | 19.0.1 Search vendor "Oracle" for product "Retail Integration Bus" and version "19.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Merchandising System Search vendor "Oracle" for product "Retail Merchandising System" | 16.0.3 Search vendor "Oracle" for product "Retail Merchandising System" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Merchandising System Search vendor "Oracle" for product "Retail Merchandising System" | 19.0.1 Search vendor "Oracle" for product "Retail Merchandising System" and version "19.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 14.1.3.2 Search vendor "Oracle" for product "Retail Service Backbone" and version "14.1.3.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 15.0.3.1 Search vendor "Oracle" for product "Retail Service Backbone" and version "15.0.3.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 16.0.3 Search vendor "Oracle" for product "Retail Service Backbone" and version "16.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Service Backbone Search vendor "Oracle" for product "Retail Service Backbone" | 19.0.1 Search vendor "Oracle" for product "Retail Service Backbone" and version "19.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 12.2.1.4.0 Search vendor "Oracle" for product "Weblogic Server" and version "12.2.1.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Weblogic Server Search vendor "Oracle" for product "Weblogic Server" | 14.1.1.0.0 Search vendor "Oracle" for product "Weblogic Server" and version "14.1.1.0.0" | - |
Affected
|