XML Entity Expansion in XMLBeans - CVE-2021-23926
Published: January 14, 2021
Vulnerability identifier: #VU49517
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23926
CWE-ID: CWE-776
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation when processing XML data. A remote attacker can pass specially crafted XML data to the application and perform XML Entity Expansion attacks.
Affected software
XMLBeans
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
IBM Sterling B2B Integrator
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Unified Mediation Bus
Atlas eDiscovery Process Management
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Oracle Business Intelligence Enterprise Edition
IBM Engineering Requirements Management DOORS Next
Oracle SOA Suite
Siebel Apps - Marketing
xmlbeans-manual
xmlbeans-javadoc
xmlbeans-scripts
xmlbeans
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Fuse
IBM Cognos Controller
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
IBM Sterling B2B Integrator
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Unified Mediation Bus
Atlas eDiscovery Process Management
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Oracle Business Intelligence Enterprise Edition
IBM Engineering Requirements Management DOORS Next
Oracle SOA Suite
Siebel Apps - Marketing
xmlbeans-manual
xmlbeans-javadoc
xmlbeans-scripts
xmlbeans
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Fuse
IBM Cognos Controller
How to mitigate CVE-2021-23926
Install updates from vendor's website.
XMLBeans - update to 3.0.0
IBM Sterling B2B Integrator - addressed in versions 6.0.0.7, 6.0.3.5, 6.1.0.3, 6.1.1.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
xmlbeans-manual - update to 2.6.0-2
xmlbeans-javadoc - update to 2.6.0-2
xmlbeans-scripts - update to 2.6.0-2
xmlbeans - update to 2.6.0-2
xmlbeans - addressed in versions 2.6.0-3.3.1, 2.6.0-150000.5.3.1
xmlbeans-scripts - update to 2.6.0-150000.5.3.1
Unified Mediation Bus - update to 4.4
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Atlas eDiscovery Process Management - update to 6.0.3.9.7
IBM Maximo Asset Management - addressed in versions 7.6.1.2.40, 7.6.1.3.10
Fuse - update to 7.10.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.22
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
IBM Sterling B2B Integrator - addressed in versions 6.0.0.7, 6.0.3.5, 6.1.0.3, 6.1.1.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
xmlbeans-manual - update to 2.6.0-2
xmlbeans-javadoc - update to 2.6.0-2
xmlbeans-scripts - update to 2.6.0-2
xmlbeans - update to 2.6.0-2
xmlbeans - addressed in versions 2.6.0-3.3.1, 2.6.0-150000.5.3.1
xmlbeans-scripts - update to 2.6.0-150000.5.3.1
Unified Mediation Bus - update to 4.4
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Atlas eDiscovery Process Management - update to 6.0.3.9.7
IBM Maximo Asset Management - addressed in versions 7.6.1.2.40, 7.6.1.3.10
Fuse - update to 7.10.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.22
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
External References
Related Security Bulletins
- XML entity expansion in XMLBeans
- Multiple vulnerabilities in Oracle Middleware Common Libraries and Tools
- XML Entity Expansion in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Siebel Apps - Marketing
- Multiple vulnerabilities in Middleware Common Libraries and Tools
- SUSE update for xmlbeans
- SUSE update for xmlbeans
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- XML external entity injection in Atlas eDiscovery Process Management
- XML entity expansion in IBM Application Performance Management
- XML Entity Expansion in Oracle SOA Suite
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- XML external entity injection in IBM Maximo Asset Management
- Multiple vulnerabilities in HPE Unified Mediation Bus (UMB)
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler 20.03 LTS SP1 update for xmlbeans
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Fuse 7.10
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- IBM SPSS Collaboration and Deployment Services update for Apache XMLBeans
- Multiple vulnerabilities in IBM Controller
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition