Information disclosure in Apache Santuario XML Security for Java - CVE-2021-40690
Published: November 16, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. A remote attacker can abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Affected software
IBM Planning Analytics Workspace
Oracle BI Publisher
Oracle Business Intelligence Enterprise Edition
IBM Business Automation Manager Open Editions
Oracle FLEXCUBE Private Banking
Oracle Application Testing Suite
Oracle Retail Service Backbone
libxml-security-java (Debian package)
libxml-security-java (Ubuntu package)
Solaris Cluster
Ubuntu
Crowd Data Center
Dell Secure Connect Gateway
Bitbucket Data Center
Oracle Financial Services Model Management and Governance
Red Hat Integration - Service Registry
Red Hat Integration Camel-K
IBM Sterling Secure Proxy
IBM Sterling B2B Integrator
IBM Observability with Instana
Crowd Server
Red Hat Single Sign-On
SecurID Authentication Manager
Oracle Communications Services Gatekeeper
Oracle Communications Instant Messaging Server
Bitbucket Server
Oracle WebLogic Server
Oracle Outside In Technology
PeopleSoft Enterprise PeopleTools
Oracle Agile PLM Framework
Oracle Commerce Guided Search
Oracle Commerce Platform
Oracle Retail Financial Integration
Oracle Retail Merchandising System
Oracle WebCenter Portal
Enterprise Manager for Peoplesoft
Oracle Retail Integration Bus
Oracle Retail Bulk Data Integration
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2021-40690
libxml-security-java (Debian package) - addressed in versions 2.0.10-2+deb10u1, 2.0.10-2+deb11u1
Crowd Data Center - update to 5.2.2
Crowd Server - update to 5.2.2
Dell Secure Connect Gateway - update to 5.14.00.10
Red Hat Single Sign-On - addressed in versions 7.4.10, 7.5.1
Bitbucket Data Center - update to 7.21.18
Bitbucket Server - update to 7.21.18
IBM Business Automation Manager Open Editions - update to 8.0.7
SecurID Authentication Manager - addressed in versions 8.6 Patch 4, 8.7 Patch 1
Red Hat Integration - Service Registry - update to 1
Red Hat Integration Camel-K - update to 1.8
libxml-security-java (Ubuntu package) - addressed in versions 2.0.10-2+deb11u1build0.20.04.1, 2.0.10-2~18.04.1
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
IBM Observability with Instana - update to 283
External References
- https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E
- https://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8@%3Cuser.poi.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html
- https://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59@%3Cissues.cxf.apache.org%3E
- https://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c@%3Ccommits.tomee.apache.org%3E
Related Security Bulletins
- Information disclosure in Apache Santuario - XML Security for Java
- Debian update for libxml-security-java
- Multiple vulnerabilities in Red Hat Single Sign-On
- Multiple vulnerabilities in Oracle Communications Messaging Server
- Information disclosure in Oracle Outside In Technology
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Oracle Retail Service Backbone
- Multiple vulnerabilities in Oracle Retail Merchandising System
- Multiple vulnerabilities in Oracle Retail Integration Bus
- Multiple vulnerabilities in Oracle Retail Financial Integration
- Multiple vulnerabilities in Oracle Retail Bulk Data Integration
- Multiple vulnerabilities in Oracle Commerce Platform
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in Oracle FLEXCUBE Private Banking
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Ubuntu update for libxml-security-java
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in Oracle Communications Services Gatekeeper
- Multiple vulnerabilities in Oracle Financial Services Model Management and Governance
- Multiple vulnerabilities in Solaris Cluster
- Multiple vulnerabilities in Oracle BI Publisher
- Multiple vulnerabilities in Oracle WebCenter Portal
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Oracle Application Testing Suite
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Information disclosure in Enterprise Manager for Peoplesoft
- Bitbucket Data Center and Server update for Apache Santuario XML Security for Java
- Atlassian Crowd Data Center and Server update for xmlsec
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Multiple vulnerabilities in Red Hat Single Sign-On 7.4
- Multiple vulnerabilities in Red Hat Integration - Service Registry
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- SecurID Authentication Manager update for third-party components
- SecurID Authentication Manager update for third-party components