AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2021-40690.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.5CVSS 3.1 · nvd@nist.gov
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSModifiedModified Oct 08, 2026

Disclosure summary

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Source-reported weakness categories

CWE-200

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2021-40690

Open original source · Updated Oct 08, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
apachesantuario_xml_security_for_java* {"versionStartIncluding":"2.2.0","versionEndExcluding":"2.2.3"}
apachecxf3.4.4
apachetomee* {"versionEndExcluding":"8.0.8"}
debiandebian_linux9.0
debiandebian_linux10.0
debiandebian_linux11.0
oracleagile_product_lifecycle_management9.3.6
oraclecommerce_guided_search11.3.2
oraclecommerce_platform11.3.2
oraclecommunications_diameter_intelligence_hub* {"versionStartIncluding":"8.2.0","versionEndIncluding":"8.2.3"}
oraclecommunications_messaging_server8.1
oracleflexcube_private_banking12.1.0
oracleoutside_in_technology8.5.5
oraclepeoplesoft_enterprise_peopletools8.58
oraclepeoplesoft_enterprise_peopletools8.59
oracleretail_bulk_data_integration16.0.3
oracleretail_financial_integration14.1.3.2
oracleretail_financial_integration15.0.3.1
oracleretail_financial_integration16.0.3
oracleretail_financial_integration19.0.1
oracleretail_integration_bus14.1.3.2
oracleretail_integration_bus15.0.3.1
oracleretail_integration_bus16.0.3
oracleretail_integration_bus19.0.1
oracleretail_merchandising_system16.0.3
oracleretail_merchandising_system19.0.1
oracleretail_service_backbone14.1.3.2
oracleretail_service_backbone15.0.3.1
oracleretail_service_backbone16.0.3
oracleretail_service_backbone19.0.1
oracleweblogic_server12.2.1.4.0
oracleweblogic_server14.1.1.0.0

Original records & references

PUBLISHED 2021-09-19T14:15:07-04:00
MODIFIED 2026-10-08T18:17:12-04:00
INGESTED 2026-10-10T20:50:20-04:00