Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21345


XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.


Published

2021-03-23T00:15:12.787

Last Modified

2025-05-23T17:41:10.117

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-94
    CWE-502
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netapp oncommand_insight - Yes
Application apache activemq < 5.15.14 Yes
Application apache activemq 5.16.0 Yes
Application apache activemq 5.16.1 Yes
Application apache jmeter < 5.5 Yes
Application xstream xstream < 1.4.16 Yes
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Operating System fedoraproject fedora 33 Yes
Operating System fedoraproject fedora 34 Yes
Operating System fedoraproject fedora 35 Yes
Application oracle banking_enterprise_default_management 2.10.0 Yes
Application oracle banking_enterprise_default_management 2.12.0 Yes
Application oracle banking_platform 2.4.0 Yes
Application oracle banking_platform 2.7.1 Yes
Application oracle banking_platform 2.9.0 Yes
Application oracle banking_platform 2.12.0 Yes
Application oracle banking_virtual_account_management 14.2.0 Yes
Application oracle banking_virtual_account_management 14.3.0 Yes
Application oracle banking_virtual_account_management 14.5.0 Yes
Application oracle business_activity_monitoring 11.1.1.9.0 Yes
Application oracle business_activity_monitoring 12.2.1.3.0 Yes
Application oracle business_activity_monitoring 12.2.1.4.0 Yes
Application oracle communications_billing_and_revenue_management_elastic_charging_engine 12.0.0.3.0 Yes
Application oracle communications_policy_management 12.5.0 Yes
Application oracle communications_unified_inventory_management 7.3.2 Yes
Application oracle communications_unified_inventory_management 7.3.4 Yes
Application oracle communications_unified_inventory_management 7.3.5 Yes
Application oracle communications_unified_inventory_management 7.4.0 Yes
Application oracle communications_unified_inventory_management 7.4.1 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle peoplesoft_enterprise_peopletools 8.59 Yes
Application oracle retail_xstore_point_of_service 16.0.6 Yes
Application oracle retail_xstore_point_of_service 17.0.4 Yes
Application oracle retail_xstore_point_of_service 18.0.3 Yes
Application oracle retail_xstore_point_of_service 19.0.2 Yes
Application oracle webcenter_portal 11.1.1.9.0 Yes
Application oracle webcenter_portal 12.2.1.3.0 Yes
Application oracle webcenter_portal 12.2.1.4.0 Yes

References