Fiche vulnérabilité
CVE-2021-39144 : faille exploitée xstream xstream (CVSS 8.5)
Description
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
En bref
- Sévérité
- Élevée (CVSS 8.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 23 août 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- xstream xstream
- debian debian linux
- fedoraproject fedora
- netapp snapmanager
- oracle business activity monitoring
- oracle commerce guided search
- oracle communications billing and revenue management elastic charging engine
- oracle communications cloud native core automated test suite
- oracle communications cloud native core binding support function
- oracle communications cloud native core policy
- oracle communications unified inventory management
- oracle retail xstore point of service
- oracle utilities framework
- oracle utilities testing accelerator
- oracle webcenter portal
Correctif et mesures
Apply updates per vendor instructions.
Références
- Fiche CVE-2021-39144 sur le NVD (NIST)
- packetstormsecurity.com/files/169859/VMware…
- github.com/x…
- lists.debian.org/debian-lts-announce/2021/09/msg00017.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- security.netapp.com/advisory/ntap-20210923-0003/
- debian.org/security/2021/dsa-5004
- oracle.com/security-alerts/cpuapr2022.html
- oracle.com/security-alerts/cpujan2022.html
- oracle.com/security-alerts/cpujul2022.html
- x-stream.github.io/CVE-2021-39144.html
- cisa.gov/known-exploited-vulnerabilities-catalog