8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
Affected (37)
Show all products
Xstream: Xstream · Debian: Debian Linux · Netapp: Snapmanager · Apache: Activemq · Oracle: Banking Cash Management, Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Platform, Banking Supply Chain Finance, Banking Trade Finance Process Management, Banking Virtual Account Management, Business Activity Monitoring, Communications Policy Management, Endeca Information Discovery Studio, Retail Xstore Point Of Service
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.2 | |
| Version 14.2 | |
| Version 14.2 | |
| Version 2.4.0 | |
| Version 14.2 | |
| Version 14.2 | |
| Version 14.2.0 | |
| Version 11.1.1.9.0 | |
| Version 12.5.0 | |
| Version 3.2.0.0 | |
| Version 16.0.6 |
References (30)
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
MitigationThird Party Advisory
Source: security-advisories@github.com
Issue TrackingMailing List
Source: security-advisories@github.com
Issue TrackingMailing List
Source: security-advisories@github.com
Issue TrackingMailing List
Source: security-advisories@github.com
Issue TrackingMailing List
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Not ApplicableThird Party Advisory
Source: security-advisories@github.com
Not ApplicableThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
ExploitMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationVendor Advisory
Timeline
No history available yet.