CVE-2021-23926
9.1
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 6.22% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-776 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-01-14 |
| Last modified | 2026-06-17 |
Affected (7)
| Vendor | Product |
|---|---|
| apache | xmlbeans |
| debian | debian linux |
| netapp | oncommand unified manager core package |
| netapp | snap creator framework |
| netapp | snapmanager |
| oracle | middleware common libraries and tools |
| oracle | peoplesoft enterprise peopletools |
References
- https://issues.apache.org/jira/browse/XMLBEANS-517
- https://lists.apache.org/thread.html/r2dc5588009dc9f0310b7382269f932cc96cae4c3901b747dda1a7fed%40%3Cjava-dev.axis.apache.org%3E
- https://lists.apache.org/thread.html/rbb01d10512098894cd5f22325588197532c64f1c818ea7e4120d40c1%40%3Cjava-dev.axis.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/06/msg00024.html
- https://poi.apache.org/
- https://security.netapp.com/advisory/ntap-20210513-0004/
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://issues.apache.org/jira/browse/XMLBEANS-517
- https://lists.apache.org/thread.html/r2dc5588009dc9f0310b7382269f932cc96cae4c3901b747dda1a7fed%40%3Cjava-dev.axis.apache.org%3E
- https://lists.apache.org/thread.html/rbb01d10512098894cd5f22325588197532c64f1c818ea7e4120d40c1%40%3Cjava-dev.axis.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/06/msg00024.html
- https://poi.apache.org/
- https://security.netapp.com/advisory/ntap-20210513-0004/
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
→ the Explorer · watch your stack · NVD