First published: Tue Oct 23 2018(Updated: )
A vulnerability was found in xstream API version 1.4.10, if the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON. This a regression of <a href="https://access.redhat.com/security/cve/CVE-2013-7285">CVE-2013-7285</a> fixed in 1.4.7 (fixed) as of BPMS 6.0.1, the regression was introduced with xstream-1.4.10 implemented in RHPAM. References: <a href="https://access.redhat.com/security/cve/cve-2013-7285">https://access.redhat.com/security/cve/cve-2013-7285</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Risk Manager | <=2.0.6 | |
redhat/xstream | <1.4.11 | 1.4.11 |
Xstream Project Xstream | =1.4.10 | |
Oracle Banking Platform | >=2.4.0<=2.10.0 | |
Oracle Banking Platform | =2.4.0 | |
Oracle Banking Platform | =2.7.1 | |
Oracle Banking Platform | =2.9.0 | |
Oracle Business Activity Monitoring | =11.1.1.9.0 | |
Oracle Business Activity Monitoring | =12.2.1.3.0 | |
Oracle Business Activity Monitoring | =12.2.1.4.0 | |
Oracle Communications Billing And Revenue Management Elastic Charging Engine | =11.3.0.9.0 | |
Oracle Communications Billing And Revenue Management Elastic Charging Engine | =12.0.0.3.0 | |
Oracle Communications Diameter Signaling Router | >=8.0.0<=8.2.2 | |
Oracle Communications Unified Inventory Management | =7.3.0 | |
Oracle Communications Unified Inventory Management | =7.4.0 | |
Oracle Endeca Information Discovery Studio | =3.2.0 | |
Oracle Endeca Information Discovery Studio | =3.2.0.0 | |
Oracle Retail Xstore Point of Service | =17.0 | |
Oracle Utilities Framework | >=4.3.0.1.0<=4.3.0.6.0 | |
Oracle Utilities Framework | =2.2.0.0.0 | |
Oracle Utilities Framework | =4.2.0.2.0 | |
Oracle Utilities Framework | =4.2.0.3.0 | |
Oracle Utilities Framework | =4.4.0.0.0 | |
Oracle WebCenter Portal | =11.1.1.9.0 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-10173 is a vulnerability in the xstream API that allows a remote attacker to execute arbitrary commands on the system.
CVE-2019-10173 is classified as critical with a severity value of 9.8.
Xstream API version 1.4.10 is affected by CVE-2019-10173.
To fix CVE-2019-10173, update to xstream API version 1.4.11 or later.
You can find more information about CVE-2019-10173 in the references provided: https://access.redhat.com/security/cve/CVE-2013-7285, https://access.redhat.com/security/cve/cve-2013-7285, http://x-stream.github.io/changes.html#1.4.11.