HIGH · 8.0

CVE-2020-26217

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only...

Vulnerability Description

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
XstreamXstream< 1.4.14
DebianDebian Linux9.0
NetappSnapmanagerAll versions
ApacheActivemq< 5.15.14
OracleBanking Cash Management14.2
OracleBanking Corporate Lending Process Management14.2
OracleBanking Credit Facilities Process Management14.2
OracleBanking Platform2.4.0
OracleBanking Supply Chain Finance14.2
OracleBanking Trade Finance Process Management14.2
OracleBanking Virtual Account Management14.2.0
OracleBusiness Activity Monitoring11.1.1.9.0
OracleCommunications Policy Management12.5.0
OracleEndeca Information Discovery Studio3.2.0.0
OracleRetail Xstore Point Of Service16.0.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-26217?

CVE-2020-26217 is a vulnerability with a CVSS score of 8.0 (HIGH). XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only...

How severe is CVE-2020-26217?

CVE-2020-26217 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-26217?

Check the references section above for vendor advisories and patch information. Affected products include: Xstream Xstream, Debian Debian Linux, Netapp Snapmanager, Apache Activemq, Oracle Banking Cash Management.