CVE-2021-40690High· 7.5▾ TwilightAll versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
7.4%
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
santuario_xml_security_for_java < 2.1.7santuario_xml_security_for_java >= 2.2.0, < 2.2.3cxf = 3.4.4tomee < 8.0.8debian_linux = 9.0debian_linux = 10.0debian_linux = 11.0agile_product_lifecycle_management = 9.3.6commerce_guided_search = 11.3.2commerce_platform = 11.3.2communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3communications_messaging_server = 8.1flexcube_private_banking = 12.1.0outside_in_technology = 8.5.5peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59retail_bulk_data_integration = 16.0.3retail_financial_integration = 14.1.3.2retail_financial_integration = 15.0.3.1retail_financial_integration = 16.0.3retail_financial_integration = 19.0.1retail_integration_bus = 14.1.3.2retail_integration_bus = 15.0.3.1retail_integration_bus = 16.0.3retail_integration_bus = 19.0.1retail_merchandising_system = 16.0.3retail_merchandising_system = 19.0.1retail_service_backbone = 14.1.3.2retail_service_backbone = 15.0.3.1retail_service_backbone = 16.0.3retail_service_backbone = 19.0.1weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0Upgrade past the affected range:
santuario_xml_security_for_java 2.2.3tomee 8.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2026-68569High· 8.1Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g
CVE-2026-84939Critical· 9.1Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …
CVE-2026-49362High· 7.5An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…
CVE-2026-49363High· 7.5An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apa…
CVE-2026-57967Critical· 9.8An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 thr…