Disclosure summary
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Source-reported weakness categories
CWE-200
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2021-40690
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| apache | santuario_xml_security_for_java | * {"versionStartIncluding":"2.2.0","versionEndExcluding":"2.2.3"} |
| apache | cxf | 3.4.4 |
| apache | tomee | * {"versionEndExcluding":"8.0.8"} |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | commerce_guided_search | 11.3.2 |
| oracle | commerce_platform | 11.3.2 |
| oracle | communications_diameter_intelligence_hub | * {"versionStartIncluding":"8.2.0","versionEndIncluding":"8.2.3"} |
| oracle | communications_messaging_server | 8.1 |
| oracle | flexcube_private_banking | 12.1.0 |
| oracle | outside_in_technology | 8.5.5 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | peoplesoft_enterprise_peopletools | 8.59 |
| oracle | retail_bulk_data_integration | 16.0.3 |
| oracle | retail_financial_integration | 14.1.3.2 |
| oracle | retail_financial_integration | 15.0.3.1 |
| oracle | retail_financial_integration | 16.0.3 |
| oracle | retail_financial_integration | 19.0.1 |
| oracle | retail_integration_bus | 14.1.3.2 |
| oracle | retail_integration_bus | 15.0.3.1 |
| oracle | retail_integration_bus | 16.0.3 |
| oracle | retail_integration_bus | 19.0.1 |
| oracle | retail_merchandising_system | 16.0.3 |
| oracle | retail_merchandising_system | 19.0.1 |
| oracle | retail_service_backbone | 14.1.3.2 |
| oracle | retail_service_backbone | 15.0.3.1 |
| oracle | retail_service_backbone | 16.0.3 |
| oracle | retail_service_backbone | 19.0.1 |
| oracle | weblogic_server | 12.2.1.4.0 |
| oracle | weblogic_server | 14.1.1.0.0 |
Original records & references
- NIST NVD record
- CVE Program record
- lists.apache.org
- lists.apache.org
- lists.apache.org — Issue Tracking, Mailing List, Patch, Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.debian.org — Mailing List, Third Party Advisory
- security.netapp.com
- www.debian.org — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org — Issue Tracking, Mailing List, Patch, Third Party Advisory
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.debian.org — Mailing List, Third Party Advisory
- security.netapp.com
- www.debian.org — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
PUBLISHED 2021-09-19T14:15:07-04:00
MODIFIED 2026-10-08T18:17:12-04:00
INGESTED 2026-10-10T20:50:20-04:00