8.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 6.0
Source: NVD
Description
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Affected (36)
Show all products
Xstream: Xstream · Debian: Debian Linux · Fedoraproject: Fedora · Netapp: Snapmanager · Oracle: Business Activity Monitoring, Commerce Guided Search, Communications Billing And Revenue Management Elastic Charging Engine, Communications Cloud Native Core Automated Test Suite, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Policy, Communications Unified Inventory Management, Retail Xstore Point Of Service, Utilities Framework, Utilities Testing Accelerator, Webcenter Portal
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.2.1.4.0 | |
| Version 11.3.2 | |
| Version 11.3 | |
| Version 1.9.0 | |
| Version 1.10.0 | |
| Version 1.14.0 | |
| Version 7.3.4 | |
| Version 16.0.6 | |
| Version 4.2.0.2.0 | |
| Version 6.0.0.1.1 | |
| Version 12.2.1.3.0 |
Related CWEs
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-502
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CWE-94
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References (25)
Source: security-advisories@github.com
ExploitThird Party AdvisoryVDB Entry
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Broken LinkMailing ListRelease Notes
Source: security-advisories@github.com
Broken LinkMailing ListRelease Notes
Source: security-advisories@github.com
Broken LinkMailing ListRelease Notes
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.