Lucene search

K
ibmIBMB0914B57985F2C98962248985AAF8BEE0B2CFA3D695BFC0ADF576FF0BA1C0D60
HistoryNov 25, 2021 - 4:33 p.m.

Security Bulletin: Vulnerability in Apache Santuario XML Security for Java may affect Cúram Social Program Management (CVE-2021-40690)

2021-11-2516:33:04
www.ibm.com
57
apache santuario xml security
ibm cúram
vulnerability
java
cve-2021-40690
security bypass
remote attack
keyinfo
xml files
curam spm 8.0.0
curam spm 7.0.11
remediation
workarounds

EPSS

0.001

Percentile

43.8%

Summary

IBM Cúram Social Program Management uses the Apache Santuario XML Security for Java libraries, for which there is a publicly known vulnerability. For this vulnerability Apache Santuario XML Security for Java could allow a remote attacker to bypass security restrictions, caused by the improper passing of the “secureValidation” property when creating a KeyInfo from a KeyInfoReference element.

Vulnerability Details

CVEID:CVE-2021-40690
**DESCRIPTION:**Apache Santuario XML Security for Java could allow a remote attacker to bypass security restrictions, caused by the improper passing of the “secureValidation” property when creating a KeyInfo from a KeyInfoReference element. An attacker could exploit this vulnerability to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/209586 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Curam SPM 8.0.0
Curam SPM 7.0.11

Remediation/Fixes

Product VRMF Remediation/First Fix
Cúram SPM

8.0.1

| Visit IBM Fix Central and upgrade to 8.0.1 or a subsequent 8.0.1 release.
Cúram SPM|

7.0.11

| Visit IBM Fix Central and upgrade to 7.0.11_iFix6 or a subsequent 7.0.11 release.

Workarounds and Mitigations

For information about all other versions, contact IBM Cúram Social Program Management customer support.

EPSS

0.001

Percentile

43.8%