Vulnerability Description
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Antisamy Project | Antisamy | < 1.6.4 |
| Oracle | Retail Back Office | 14.0 |
| Oracle | Retail Central Office | 14.0 |
| Oracle | Retail Returns Management | 14.0 |
| Oracle | Banking Enterprise Default Management | 2.6.2 |
| Oracle | Banking Enterprise Default Managment | >= 2.3.0, <= 2.4.0 |
| Oracle | Banking Party Management | 2.7.0 |
| Oracle | Banking Platform | >= 2.3.0, <= 2.4.1 |
| Oracle | Insurance Policy Administration | 11.0.2 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.3.0 |
| Netapp | Active Iq Unified Manager | - |
Related Weaknesses (CWE)
References
- https://github.com/nahsra/antisamy/pull/87PatchThird Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatchThird Party Advisory
- https://github.com/nahsra/antisamy/pull/87PatchThird Party Advisory
- https://github.com/nahsra/antisamy/releases/tag/v1.6.4PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatchThird Party Advisory
FAQ
What is CVE-2021-35043?
CVE-2021-35043 is a vulnerability with a CVSS score of 6.1 (MEDIUM). OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for...
How severe is CVE-2021-35043?
CVE-2021-35043 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35043?
Check the references section above for vendor advisories and patch information. Affected products include: Antisamy Project Antisamy, Oracle Retail Back Office, Oracle Retail Central Office, Oracle Retail Returns Management, Oracle Banking Enterprise Default Management.