CVE-2021-23926

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:xmlbeans:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:oracle:*:*
cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:sap:*:*
cpe:2.3:a:netapp:oncommand_unified_manager_core_package:-:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*

Information

Published : 2021-01-14 15:15

Updated : 2022-07-25 18:15


NVD link : CVE-2021-23926

Mitre link : CVE-2021-23926


JSON object : View

Products Affected

debian

  • debian_linux

netapp

  • snap_creator_framework
  • snapmanager
  • oncommand_unified_manager_core_package

apache

  • xmlbeans

oracle

  • peoplesoft_enterprise_peopletools
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')