Fiche vulnérabilité
CVE-2021-21344 : faille critique netapp oncommand insight (CVSS 9.8)
Description
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 23 mars 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- netapp oncommand insight
- apache activemq
- apache jmeter
- xstream xstream
- debian debian linux
- fedoraproject fedora
- oracle banking enterprise default management
- oracle banking platform
- oracle banking virtual account management
- oracle business activity monitoring
- oracle communications billing and revenue management elastic charging engine
- oracle communications policy management
- oracle communications unified inventory management
- oracle mysql server
- oracle retail xstore point of service
- oracle webcenter portal
Références
- Fiche CVE-2021-21344 sur le NVD (NIST)
- x-stream.github.io/changes.html
- github.com/x…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.debian.org/debian-lts-announce/2021/04/msg00002.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- security.netapp.com/advisory/ntap-20210430-0002/
- debian.org/security/2021/dsa-5004
- oracle.com//security-alerts/cpujul2021.html
- oracle.com/security-alerts/cpujan2022.html
- oracle.com/security-alerts/cpuoct2021.html
- x-stream.github.io/CVE-2021-21344.html
- x-stream.github.io/security.html