Information disclosure in Apache Santuario XML Security for Java - CVE-2021-40690

 

Information disclosure in Apache Santuario XML Security for Java - CVE-2021-40690

Published: November 16, 2021


Vulnerability identifier: #VU58198
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-40690
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. A remote attacker can abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.


Affected software

Apache Santuario XML Security for Java
IBM Planning Analytics Workspace
Oracle BI Publisher
Oracle Business Intelligence Enterprise Edition
IBM Business Automation Manager Open Editions
Oracle FLEXCUBE Private Banking
Oracle Application Testing Suite
Oracle Retail Service Backbone
libxml-security-java (Debian package)
libxml-security-java (Ubuntu package)
Solaris Cluster
Ubuntu
Crowd Data Center
Dell Secure Connect Gateway
Bitbucket Data Center
Oracle Financial Services Model Management and Governance
Red Hat Integration - Service Registry
Red Hat Integration Camel-K
IBM Sterling Secure Proxy
IBM Sterling B2B Integrator
IBM Observability with Instana
Crowd Server
Red Hat Single Sign-On
SecurID Authentication Manager
Oracle Communications Services Gatekeeper
Oracle Communications Instant Messaging Server
Bitbucket Server
Oracle WebLogic Server
Oracle Outside In Technology
PeopleSoft Enterprise PeopleTools
Oracle Agile PLM Framework
Oracle Commerce Guided Search
Oracle Commerce Platform
Oracle Retail Financial Integration
Oracle Retail Merchandising System
Oracle WebCenter Portal
Enterprise Manager for Peoplesoft
Oracle Retail Integration Bus
Oracle Retail Bulk Data Integration
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2021-40690

Install updates from vendor's website.

Apache Santuario XML Security for Java - addressed in versions 2.1.7, 2.2.3
libxml-security-java (Debian package) - addressed in versions 2.0.10-2+deb10u1, 2.0.10-2+deb11u1
Crowd Data Center - update to 5.2.2
Crowd Server - update to 5.2.2
Dell Secure Connect Gateway - update to 5.14.00.10
Red Hat Single Sign-On - addressed in versions 7.4.10, 7.5.1
Bitbucket Data Center - update to 7.21.18
Bitbucket Server - update to 7.21.18
IBM Business Automation Manager Open Editions - update to 8.0.7
SecurID Authentication Manager - addressed in versions 8.6 Patch 4, 8.7 Patch 1
Red Hat Integration - Service Registry - update to 1
Red Hat Integration Camel-K - update to 1.8
libxml-security-java (Ubuntu package) - addressed in versions 2.0.10-2+deb11u1build0.20.04.1, 2.0.10-2~18.04.1
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
IBM Observability with Instana - update to 283

External References

Related Security Bulletins