Aller au contenu

Fiche vulnérabilité

CVE-2021-39149 : faille élevée xstream xstream (CVSS 8.5)

Description

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

En bref

Sévérité
Élevée (CVSS 8.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
23 août 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • xstream xstream
  • fedoraproject fedora
  • debian debian linux
  • netapp snapmanager
  • oracle business activity monitoring
  • oracle commerce guided search
  • oracle communications billing and revenue management elastic charging engine
  • oracle communications cloud native core automated test suite
  • oracle communications cloud native core binding support function
  • oracle communications cloud native core policy
  • oracle communications unified inventory management
  • oracle retail xstore point of service
  • oracle utilities framework
  • oracle utilities testing accelerator
  • oracle webcenter portal

Références

Rechercher une autre vulnérabilité dans la base CVE