---
id: CVE-2021-40690
title: >-
  All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and
  2.1.7 are vulnerable to an issue where the "secureValidation" property is not
  passed correctly when creating a KeyInfo from a KeyInfoReference element
summary: >-
  All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and
  2.1.7 are vulnerable to an issue where the "secureValidation" property is not
  passed correctly when creating a KeyInfo from a KeyInfoReference element. This
  allo…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: apache
product: santuario_xml_security_for_java
affected:
  - santuario_xml_security_for_java < 2.1.7
  - 'santuario_xml_security_for_java >= 2.2.0, < 2.2.3'
  - cxf = 3.4.4
  - tomee < 8.0.8
  - debian_linux = 9.0
  - debian_linux = 10.0
  - debian_linux = 11.0
  - agile_product_lifecycle_management = 9.3.6
  - commerce_guided_search = 11.3.2
  - commerce_platform = 11.3.2
  - 'communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0'
  - 'communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3'
  - communications_messaging_server = 8.1
  - flexcube_private_banking = 12.1.0
  - outside_in_technology = 8.5.5
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - retail_bulk_data_integration = 16.0.3
  - retail_financial_integration = 14.1.3.2
  - retail_financial_integration = 15.0.3.1
  - retail_financial_integration = 16.0.3
  - retail_financial_integration = 19.0.1
  - retail_integration_bus = 14.1.3.2
  - retail_integration_bus = 15.0.3.1
  - retail_integration_bus = 16.0.3
  - retail_integration_bus = 19.0.1
  - retail_merchandising_system = 16.0.3
  - retail_merchandising_system = 19.0.1
  - retail_service_backbone = 14.1.3.2
  - retail_service_backbone = 15.0.3.1
  - retail_service_backbone = 16.0.3
  - retail_service_backbone = 19.0.1
  - weblogic_server = 12.2.1.4.0
  - weblogic_server = 14.1.1.0.0
patched:
  - santuario_xml_security_for_java 2.2.3
  - tomee 8.0.8
published: '2021-09-19'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-40690'
references:
  - url: >-
      https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59%40%3Cissues.cxf.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8%40%3Cuser.poi.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20230818-0002/'
    label: security@apache.org
  - url: 'https://www.debian.org/security/2021/dsa-5010'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59%40%3Cissues.cxf.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8%40%3Cuser.poi.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20230818-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-5010'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-40690.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-40690'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2011190'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-40690'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-40690'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5149'
  - url: 'https://access.redhat.com/errata/RHSA-2025:4226'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5150'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0151'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5151'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0164'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0152'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5154'
  - url: 'https://access.redhat.com/errata/RHSA-2022:6407'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1013'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0501'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0155'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0146'
  - url: 'https://access.redhat.com/errata/RHSA-2022:5532'
  - url: 'https://access.redhat.com/errata/RHSA-2021:4679'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5170'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.0738
epssPercentile: 0.94194
ingestedAt: '2026-08-25T17:29:31.440Z'
---

## Overview

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

## Affected

- `santuario_xml_security_for_java < 2.1.7`
- `santuario_xml_security_for_java >= 2.2.0, < 2.2.3`
- `cxf = 3.4.4`
- `tomee < 8.0.8`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `agile_product_lifecycle_management = 9.3.6`
- `commerce_guided_search = 11.3.2`
- `commerce_platform = 11.3.2`
- `communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0`
- `communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3`
- `communications_messaging_server = 8.1`
- `flexcube_private_banking = 12.1.0`
- `outside_in_technology = 8.5.5`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `retail_bulk_data_integration = 16.0.3`
- `retail_financial_integration = 14.1.3.2`
- `retail_financial_integration = 15.0.3.1`
- `retail_financial_integration = 16.0.3`
- `retail_financial_integration = 19.0.1`
- `retail_integration_bus = 14.1.3.2`
- `retail_integration_bus = 15.0.3.1`
- `retail_integration_bus = 16.0.3`
- `retail_integration_bus = 19.0.1`
- `retail_merchandising_system = 16.0.3`
- `retail_merchandising_system = 19.0.1`
- `retail_service_backbone = 14.1.3.2`
- `retail_service_backbone = 15.0.3.1`
- `retail_service_backbone = 16.0.3`
- `retail_service_backbone = 19.0.1`
- `weblogic_server = 12.2.1.4.0`
- `weblogic_server = 14.1.1.0.0`

## Remediation

Upgrade past the affected range:

- `santuario_xml_security_for_java 2.2.3`
- `tomee 8.0.8`

## Vendor advisories

- **RHSA-2021:5149** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 6 Server · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5149)
- **RHSA-2025:4226** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · released 2025-04-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:4226)
- **RHSA-2021:5150** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 7 Server · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5150)
- **RHSA-2022:0151** · Red Hat · fixed in: Red Hat Single Sign-On 7.5 for RHEL 7 Server · released 2022-01-17 · [advisory](https://access.redhat.com/errata/RHSA-2022:0151)
- **RHSA-2021:5151** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for BaseOS-8 · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5151)
- **RHSA-2022:0164** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2022-01-18 · [advisory](https://access.redhat.com/errata/RHSA-2022:0164)
- **RHSA-2022:0152** · Red Hat · fixed in: Red Hat Single Sign-On 7.5 for RHEL 8 · released 2022-01-17 · [advisory](https://access.redhat.com/errata/RHSA-2022:0152)
- **RHSA-2021:5154** · Red Hat · fixed in: EAP 7.3.10 GA · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5154)
- **RHSA-2022:6407** · Red Hat · fixed in: RHAF Camel-K 1.8 · released 2022-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2022:6407)
- **RHSA-2022:1013** · Red Hat · fixed in: RHINT Camel-Q 2.2.1 · released 2022-03-22 · [advisory](https://access.redhat.com/errata/RHSA-2022:1013)
- **RHSA-2022:0501** · Red Hat · fixed in: RHINT Service Registry 2.0.3 GA · released 2022-02-09 · [advisory](https://access.redhat.com/errata/RHSA-2022:0501)
- **Red Hat VEX** · Moderate · affected: Logging Subsystem for Red Hat OpenShift, Red Hat Integration Camel Quarkus 1, Red Hat Integration Service Registry, Red Hat JBoss Data Virtualization 6, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Fuse 6, … · no fix planned: Red Hat JBoss Data Virtualization 6, Red Hat JBoss Fuse 6, Red Hat JBoss Fuse Service Works 6, Red Hat JBoss Operations Network 3, … · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-40690.json)
