ZeroHour

CVE-2021-23926

CVSS 3.1
9.1 critical
EPSS
6%p93
Published
()
Modified
Description

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Vendors
apachenetappdebianoracle
Products
xmlbeans, oncommand unified manager core package, snap creator framework, snapmanager, debian linux, middleware common libraries and tools, peoplesoft enterprise peopletools
Weakness
CWE-776
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.