8.5

CVE-2021-39148

Exploit

XStream is vulnerable to an Arbitrary Code Execution attack

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xstream ≫ Xstream Version < 1.4.18
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Snapmanager Version - SwPlatform oracle
Netapp ≫ Snapmanager Version - SwPlatform sap
Oracle ≫ Business Activity Monitoring Version 12.2.1.4.0
Oracle ≫ Commerce Guided Search Version 11.3.2
Oracle ≫ Utilities Framework Version 4.2.0.2.0
Oracle ≫ Utilities Framework Version 4.2.0.3.0
Oracle ≫ Utilities Framework Version 4.3.0.1.0
Oracle ≫ Utilities Framework Version 4.3.0.6.0
Oracle ≫ Utilities Framework Version 4.4.0.0.0
Oracle ≫ Utilities Framework Version 4.4.0.2.0
Oracle ≫ Utilities Framework Version 4.4.0.3.0
Oracle ≫ Utilities Testing Accelerator Version 6.0.0.1.1
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Oracle ≫ Webcenter Portal Version 12.2.1.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.74% 0.908
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.5 1.8 6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
security-advisories@github.com 8.5 1.8 6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Third Party Advisory
https://www.debian.org/security/2021/dsa-5004
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20210923-0003/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
Mailing List
https://github.com/x-stream/xstream/security/advisories/GHSA-qrx8-8545-4wg2
Third Party Advisory
https://x-stream.github.io/CVE-2021-39148.html
Third Party Advisory
Exploit