Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2021-23926
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
54.6%
CVSS Severity
CVSS v3 Score
9.1
CVSS v2 Score
6.4
References
https://issues.apache.org/jira/browse/XMLBEANS-517
https://lists.apache.org/thread.html/r2dc5588009dc9f0310b7382269f932cc96cae4c3901b747dda1a7fed%40%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/rbb01d10512098894cd5f22325588197532c64f1c818ea7e4120d40c1%40%3Cjava-dev.axis.apache.org%3E
https://lists.debian.org/debian-lts-announce/2021/06/msg00024.html
https://poi.apache.org/
https://security.netapp.com/advisory/ntap-20210513-0004/
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://issues.apache.org/jira/browse/XMLBEANS-517
https://lists.apache.org/thread.html/r2dc5588009dc9f0310b7382269f932cc96cae4c3901b747dda1a7fed%40%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/rbb01d10512098894cd5f22325588197532c64f1c818ea7e4120d40c1%40%3Cjava-dev.axis.apache.org%3E
https://lists.debian.org/debian-lts-announce/2021/06/msg00024.html
https://poi.apache.org/
https://security.netapp.com/advisory/ntap-20210513-0004/
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
Products affected by CVE-2021-23926
Apache
»
Xmlbeans
»
Version:
2.6.0
cpe:2.3:a:apache:xmlbeans:2.6.0
Netapp
»
Oncommand Unified Manager Core Package
»
Version:
N/A
cpe:2.3:a:netapp:oncommand_unified_manager_core_package:-
Netapp
»
Snap Creator Framework
»
Version:
N/A
cpe:2.3:a:netapp:snap_creator_framework:-
Netapp
»
Snapmanager
»
Version:
N/A
cpe:2.3:a:netapp:snapmanager:-
Oracle
»
Middleware Common Libraries And Tools
»
Version:
12.2.1.3.0
cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.3.0
Oracle
»
Middleware Common Libraries And Tools
»
Version:
12.2.1.4.0
cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0
Oracle
»
Peoplesoft Enterprise Peopletools
»
Version:
8.57
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57
Oracle
»
Peoplesoft Enterprise Peopletools
»
Version:
8.58
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58
Oracle
»
Peoplesoft Enterprise Peopletools
»
Version:
8.59
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved