DBeaver < 21.2.3 XXE Vulnerability

high Nessus Plugin ID 297220

Synopsis

An updater application installed on the remote Windows host is affected by a XXE vulnerability.

Description

The version of DBeaver installed on the remote Windows host is prior to 21.2.3. It is, therefore, affected by the following XXE vulnerability:

- The dbeaver is vulnerable to XML External Entity (XXE). An attacker that is able to provide a crafted XML file as input to the parseDocument() function in the 'XMLUtils.java' file may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.(CVE-2021-3836)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to DBeaver 21.2.3 or later.

See Also

http://www.nessus.org/u?be3befe8

http://www.nessus.org/u?545b101f

Plugin Details

Severity: High

ID: 297220

File Name: dbeaver_21_2_3.nasl

Version: 1.1

Type: local

Agent: windows

Family: Windows

Published: 1/30/2026

Updated: 1/30/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: High

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2021-3836

CVSS v3

Risk Factor: High

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:dbeaver:dbeaver

Required KB Items: SMB/Registry/Enumerated, installed_sw/DBeaver

Patch Publication Date: 10/17/2021

Vulnerability Publication Date: 9/21/2021

Reference Information

CVE: CVE-2021-3836

IAVA: 2026-A-0083