XML Entity Expansion in XMLBeans - CVE-2021-23926

 

XML Entity Expansion in XMLBeans - CVE-2021-23926

Published: January 14, 2021


Vulnerability identifier: #VU49517
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23926
CWE-ID: CWE-776
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper input validation when processing XML data. A remote attacker can pass specially crafted XML data to the application and perform XML Entity Expansion attacks.


Affected software

XMLBeans
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
IBM Sterling B2B Integrator
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Unified Mediation Bus
Atlas eDiscovery Process Management
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Oracle Business Intelligence Enterprise Edition
IBM Engineering Requirements Management DOORS Next
Oracle SOA Suite
Siebel Apps - Marketing
xmlbeans-manual
xmlbeans-javadoc
xmlbeans-scripts
xmlbeans
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Fuse
IBM Cognos Controller

How to mitigate CVE-2021-23926

Install updates from vendor's website.

XMLBeans - update to 3.0.0
IBM Sterling B2B Integrator - addressed in versions 6.0.0.7, 6.0.3.5, 6.1.0.3, 6.1.1.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
xmlbeans-manual - update to 2.6.0-2
xmlbeans-javadoc - update to 2.6.0-2
xmlbeans-scripts - update to 2.6.0-2
xmlbeans - update to 2.6.0-2
xmlbeans - addressed in versions 2.6.0-3.3.1, 2.6.0-150000.5.3.1
xmlbeans-scripts - update to 2.6.0-150000.5.3.1
Unified Mediation Bus - update to 4.4
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
Atlas eDiscovery Process Management - update to 6.0.3.9.7
IBM Maximo Asset Management - addressed in versions 7.6.1.2.40, 7.6.1.3.10
Fuse - update to 7.10.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.22
IBM Cognos Controller - addressed in versions 11.0.1 FP7, 11.1.2 FP1
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6

External References

Related Security Bulletins