CVE-2021-3517

HIGHCVSS 8.6/10EPSS 8.28%

Last modified

CVE-2021-3517 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. EPSS estimates a 8.28% chance of exploitation in the next 30 days.

Description

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.

Metrics

CVSS 3.1
8.6/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

EPSS Probability
8.28%

94.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
XmlsoftLibxml2< 2.9.11
RedhatJboss Core ServicesAll versions
RedhatEnterprise Linux8.0
FedoraprojectFedora33
FedoraprojectFedora34
DebianDebian Linux9.0
NetappActive Iq Unified ManagerAll versions
NetappClustered Data OntapAll versions
NetappClustered Data Ontap Antivirus ConnectorAll versions
NetappE-Series Santricity Os Controller>= 11.0.0, <= 11.70.1
NetappE-Series Santricity Storage ManagerAll versions
NetappE-Series Santricity Web ServicesAll versions
NetappHci Management NodeAll versions
NetappManageability Software Development KitAll versions
NetappOncommand InsightAll versions
NetappOncommand Workflow AutomationAll versions
NetappOntap Select Deploy Administration UtilityAll versions
NetappSantricity Unified ManagerAll versions
NetappSnapdriveAll versions
NetappSnapmanagerAll versions
NetappSolidfireAll versions
NetappHci H410c FirmwareAll versions
OracleCommunications Cloud Native Core Network Function Cloud Native Environment1.10.0
OracleEnterprise Manager Base Platform13.4.0.0
OracleEnterprise Manager Base Platform13.5.0.0
OracleMysql Workbench<= 8.0.26
OracleOpenjdk8Update301
OraclePeoplesoft Enterprise Peopletools8.58
OracleReal User Experience Insight13.4.1.0
OracleReal User Experience Insight13.5.1.0
OracleZfs Storage Appliance Kit8.8

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3517?
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
How severe is CVE-2021-3517?
CVE-2021-3517 has a CVSS score of 8.6/10 (HIGH severity). The EPSS model estimates a 8.28% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3517?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3517?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST