Vulnerability Description
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml2 | < 2.9.11 |
| Redhat | Jboss Core Services | - |
| Oracle | Zfs Storage Appliance Kit | 8.8 |
| Netapp | Active Iq Unified Manager | - |
| Netapp | Cloud Backup | - |
| Netapp | Clustered Data Ontap | - |
| Netapp | Clustered Data Ontap Antivirus Connector | - |
| Netapp | Manageability Software Development Kit | - |
| Netapp | Ontap Select Deploy Administration Utility | - |
| Netapp | Smi-S Provider | - |
| Netapp | Snapdrive | - |
| Netapp | H410C Firmware | - |
| Netapp | H410C | - |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H300E Firmware | - |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1950515Issue TrackingPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0007/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1950515Issue TrackingPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0007/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2021-3541?
CVE-2021-3541 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
How severe is CVE-2021-3541?
CVE-2021-3541 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3541?
Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2, Redhat Jboss Core Services, Oracle Zfs Storage Appliance Kit, Netapp Active Iq Unified Manager, Netapp Cloud Backup.