7.5

CVE-2021-40690

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Data is provided by the National Vulnerability Database (NVD)
ApacheSantuario Xml Security For Java Version >= 2.2.0 < 2.2.3
ApacheCxf Version3.4.4
ApacheTomee Version < 8.0.8
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
DebianDebian Linux Version11.0
OracleAgile Plm Version9.3.6
OracleCommerce Guided Search Version11.3.2
OracleCommerce Platform Version11.3.2
OracleCommunications Diameter Intelligence Hub Version >= 8.0.0 <= 8.1.0
OracleCommunications Diameter Intelligence Hub Version >= 8.2.0 <= 8.2.3
OracleFlexcube Private Banking Version12.1.0
OracleOutside In Technology Version8.5.5
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.3.1
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.3.1
OracleRetail Integration Bus Version16.0.3
OracleRetail Integration Bus Version19.0.1
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version16.0.3
OracleRetail Service Backbone Version19.0.1
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.33% 0.55
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.