CVEs (37)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreMay 23, 2025 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the proces...Show more |
6Apache DebianFedoraproject+3 more17Activemq Banking Enterprise Default ManagementBanking Platform+14 moreMay 23, 2025 Mar 23, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publ...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreMay 23, 2025 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and wil...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreMay 23, 2025 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host onl...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreMay 23, 2025 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host onl...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreMay 23, 2025 Mar 23, 2021 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreMay 23, 2025 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host onl...Show more |
6Apache DebianFedoraproject+3 more15Activemq Banking Enterprise Default ManagementBanking Platform+12 moreMay 23, 2025 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the...Show more |
6Apache DebianFedoraproject+3 more15Activemq Banking Enterprise Default ManagementBanking Platform+12 moreMay 23, 2025 Mar 23, 2021 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the...Show more |
6Apache DebianFedoraproject+3 more13Activemq Banking Enterprise Default ManagementBanking Platform+10 moreMay 23, 2025 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on...Show more |
4Apache DebianFedoraproject+1 more4Debian Linux FedoraStruts+1 moreMay 23, 2025 Dec 16, 2020 N/A· v4 6.8 MEDIUM· v3 6.4 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remo...Show more |
4Apache DebianFedoraproject+1 more4Debian Linux FedoraStruts+1 moreMay 23, 2025 Dec 16, 2020 N/A· v4 7.7 HIGH· v3 5.0 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remot...Show more |
5Apache DebianNetapp+2 more15Activemq Banking Cash ManagementBanking Corporate Lending Process Management+12 moreMay 23, 2025 Nov 16, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on b...Show more |
2Oracle Xstream10Banking Platform Business Activity MonitoringCommunications Billing And Revenue Management Elastic Charging Engine+7 moreMay 14, 2025 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary...Show more |
3Apache OracleXstream3Activemq Endeca Information Discovery StudioXstreamMay 23, 2025 May 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarsh...Show more |
3Debian RedhatXstream4Debian Linux FuseJboss Middleware+1 moreMay 23, 2025 Apr 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux FedoraJboss Middleware+1 moreMay 23, 2025 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow...Show more |