HIGH · 7.5

CVE-2021-29505

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the...

Vulnerability Description

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
XstreamXstream< 1.4.17
DebianDebian Linux9.0
FedoraprojectFedora33
NetappSnapmanager-
OracleBanking Cash Management14.2
OracleBanking Corporate Lending Process Management14.2.0
OracleBanking Credit Facilities Process Management14.2.0
OracleBanking Supply Chain Finance14.2.0
OracleBanking Trade Finance Process Management14.5.0
OracleBusiness Activity Monitoring11.1.1.9.0
OracleCommunications Brm - Elastic Charging Engine11.3
OracleCommunications Unified Inventory Management7.3.4
OracleEnterprise Manager Ops Center12.4.0.0
OracleRetail Customer Insights15.0.2
OracleRetail Xstore Point Of Service16.0.6
OracleWebcenter Portal12.2.1.3.0
OracleWebcenter Sites12.2.1.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-29505?

CVE-2021-29505 is a vulnerability with a CVSS score of 7.5 (HIGH). XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the...

How severe is CVE-2021-29505?

CVE-2021-29505 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-29505?

Check the references section above for vendor advisories and patch information. Affected products include: Xstream Xstream, Debian Debian Linux, Fedoraproject Fedora, Netapp Snapmanager, Oracle Banking Cash Management.