← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-3517

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
Exploitability:3.9
Impact Score:4.8
EPSS Probability:8.28%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
xmlsoft libxml2 all
redhat jboss_core_services all
redhat enterprise_linux 8.0
fedoraproject fedora 33, 34
debian debian_linux 9.0
netapp active_iq_unified_manager all
netapp clustered_data_ontap all
netapp clustered_data_ontap_antivirus_connector all
netapp e-series_santricity_os_controller all
netapp e-series_santricity_storage_manager all
netapp e-series_santricity_web_services all
netapp hci_management_node all
netapp manageability_software_development_kit all
netapp oncommand_insight all
netapp oncommand_workflow_automation all
netapp ontap_select_deploy_administration_utility all
netapp santricity_unified_manager all
netapp snapdrive all
netapp snapmanager all
netapp solidfire all
netapp hci_h410c_firmware all
netapp hci_h410c all
oracle communications_cloud_native_core_network_function_cloud_native_environment 1.10.0
oracle enterprise_manager_base_platform 13.4.0.0, 13.5.0.0
oracle mysql_workbench all
oracle openjdk 8
oracle peoplesoft_enterprise_peopletools 8.58
oracle real_user_experience_insight 13.4.1.0, 13.5.1.0
oracle zfs_storage_appliance_kit 8.8

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
8.280%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2021-04-27T00:00:00
Published2021-05-19T13:45:00
Last Updated2025-12-02T21:34:00

LINK COPIED TO CLIPBOARD