← Back

CVE-2020-26217

Published: Nov 16, 2020Modified: May 23, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

Affected (37)

Products: Xstream: Xstream · Debian: Debian Linux · Netapp: Snapmanager · +2 more
Show all products
1 product
Xstream
1 product
Debian Linux
1 product
Snapmanager
1 product
Activemq
11 products
Banking Cash Management
Banking Platform
Banking Supply Chain Finance
Business Activity Monitoring
Communications Policy Management
Retail Xstore Point Of Service
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.4.14
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 5.15.14
Version 5.16.0
Configuration E
30 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 2.4.0
Version 2.7.1
Version 2.9.0
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2
Version 14.3
Version 14.5
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 12.5.0
Version 3.2.0.0
Oracle
Version 16.0.6
Version 17.0.4
Version 18.0.3
Version 19.0.2

References (30)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
MitigationThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Not ApplicableThird Party Advisory
Source: security-advisories@github.com
Not ApplicableThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
ExploitMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationVendor Advisory

Timeline

No history available yet.