imPC@ndo IT

Tracker / CVE-2021-23926

CVE-2021-23926

Critical 9.1

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Affected products and versions

apache xmlbeans · … → 2.6.0
debian debian_linux
netapp oncommand_unified_manager_core_package
netapp snap_creator_framework
netapp snapmanager
oracle middleware_common_libraries_and_tools
oracle peoplesoft_enterprise_peopletools

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References