MEDIUM · 6.5

CVE-2021-39140

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on ...

Vulnerability Description

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
XstreamXstream< 1.4.18
DebianDebian Linux9.0
FedoraprojectFedora33
NetappSnapmanager-
OracleBusiness Activity Monitoring12.2.1.4.0
OracleCommerce Guided Search11.3.2
OracleCommunications Billing And Revenue Management Elastic Charging Engine11.3
OracleCommunications Cloud Native Core Automated Test Suite1.9.0
OracleCommunications Cloud Native Core Binding Support Function1.10.0
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Unified Inventory Management7.3.4
OracleRetail Xstore Point Of Service16.0.6
OracleUtilities Framework4.2.0.2.0
OracleUtilities Testing Accelerator6.0.0.1.1
OracleWebcenter Portal12.2.1.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-39140?

CVE-2021-39140 is a vulnerability with a CVSS score of 6.5 (MEDIUM). XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on ...

How severe is CVE-2021-39140?

CVE-2021-39140 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-39140?

Check the references section above for vendor advisories and patch information. Affected products include: Xstream Xstream, Debian Debian Linux, Fedoraproject Fedora, Netapp Snapmanager, Oracle Business Activity Monitoring.