First published: Fri Mar 12 2021(Updated: )
Last updated 22 August 2024
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/xstream | <1.4.16 | 1.4.16 |
debian/libxstream-java | 1.4.15-3+deb11u2 1.4.15-3+deb11u3 1.4.20-1+deb12u1 1.4.21-1 | |
XStream | <1.4.16 | |
Debian | =9.0 | |
Debian | =10.0 | |
Debian | =11.0 | |
Fedora | =33 | |
Fedora | =34 | |
Fedora | =35 | |
oracle banking enterprise default management | =2.10.0 | |
oracle banking enterprise default management | =2.12.0 | |
oracle banking platform | =2.4.0 | |
oracle banking platform | =2.7.1 | |
oracle banking platform | =2.9.0 | |
oracle banking platform | =2.12.0 | |
oracle business activity monitoring | =11.1.1.9.0 | |
oracle business activity monitoring | =12.2.1.3.0 | |
oracle business activity monitoring | =12.2.1.4.0 | |
oracle communications billing and revenue management elastic charging engine | =12.0.0.3.0 | |
Oracle Communications Unified Inventory Management | =7.3.2 | |
Oracle Communications Unified Inventory Management | =7.3.4 | |
Oracle Communications Unified Inventory Management | =7.3.5 | |
Oracle Communications Unified Inventory Management | =7.4.0 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle Retail Xstore Office Cloud Service | =16.0.6 | |
Oracle Retail Xstore Office Cloud Service | =17.0.4 | |
Oracle Retail Xstore Office Cloud Service | =18.0.3 | |
Oracle Retail Xstore Office Cloud Service | =19.0.2 | |
Oracle WebCenter Portal | =11.1.1.9.0 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-21341 is a vulnerability in XStream, a Java library used to serialize objects to XML and back again.
CVE-2021-21341 has a severity rating of 7.5, which is considered high.
CVE-2021-21341 may allow a remote attacker to allocate 100% CPU time on the target system, resulting in a denial of service.
XStream versions up to 1.4.16 are affected by CVE-2021-21341.
To fix CVE-2021-21341, update XStream to version 1.4.16 or higher.