CVE-2021-40690

Aliases:GHSA-j8wc-gxx9-82hx
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 19 Sept 2021, 00:00
Last modified:04 Aug 2024, 02:51

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.28% LOW
0% probability -0.10%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Sept 2021, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 02:51
Last Modified
Vulnerability information updated

Description

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.28% Percentile: 51%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • apache software foundationapache santuario

    ≥ XML Security for Java, < 2.2.3,2.1.7

  • apachecxf

    3.4.4

  • apachesantuario_xml_security_for_java

    < 2.1.7 | ≥ 2.2.0, < 2.2.3

  • apachetomee

    < 8.0.8

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • org.apache.santuarioxmlsec

    ≥ 2.2.0, < 2.2.3 | < 2.1.7

  • oracleagile_plm

    9.3.6

  • oraclecommerce_guided_search

    11.3.2

  • oraclecommerce_platform

    11.3.2

  • oraclecommunications_diameter_intelligence_hub

    ≥ 8.0.0, ≤ 8.1.0 | ≥ 8.2.0, ≤ 8.2.3

  • oraclecommunications_messaging_server

    8.1

  • oracleflexcube_private_banking

    12.1.0

  • oracleoutside_in_technology

    8.5.5

  • oraclepeoplesoft_enterprise_peopletools

    8.58 | 8.59

  • oracleretail_bulk_data_integration

    16.0.3

  • oracleretail_financial_integration

    14.1.3.2 | 15.0.3.1 | 16.0.3 | 19.0.1

  • oracleretail_integration_bus

    14.1.3.2 | 15.0.3.1 | 16.0.3 | 19.0.1

  • oracleretail_merchandising_system

    16.0.3 | 19.0.1

  • oracleretail_service_backbone

    14.1.3.2 | 15.0.3.1 | 16.0.3 | 19.0.1

  • UnknownWebLogic Server

    12.2.1.4.0 | 14.1.1.0.0

References (24)