First published: Sun Aug 22 2021(Updated: )
XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/xstream | <0:1.3.1-16.el7_9 | 0:1.3.1-16.el7_9 |
debian/libxstream-java | 1.4.11.1-1+deb10u3 1.4.11.1-1+deb10u4 1.4.15-3+deb11u2 1.4.20-1 | |
redhat/xstream | <1.4.18 | 1.4.18 |
Xstream Project Xstream | <1.4.18 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Oracle Business Activity Monitoring | =12.2.1.4.0 | |
Oracle Commerce Guided Search | =11.3.2 | |
Oracle Communications Billing And Revenue Management Elastic Charging Engine | =11.3 | |
Oracle Communications Billing And Revenue Management Elastic Charging Engine | =12.0 | |
Oracle Communications Cloud Native Core Automated Test Suite | =1.9.0 | |
Oracle Communications Cloud Native Core Binding Support Function | =1.10.0 | |
Oracle Communications Cloud Native Core Policy | =1.14.0 | |
Oracle Communications Unified Inventory Management | =7.3.4 | |
Oracle Communications Unified Inventory Management | =7.3.5 | |
Oracle Communications Unified Inventory Management | =7.4.0 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle Communications Unified Inventory Management | =7.4.2 | |
Oracle Retail Xstore Point of Service | =16.0.6 | |
Oracle Retail Xstore Point of Service | =17.0.4 | |
Oracle Retail Xstore Point of Service | =18.0.3 | |
Oracle Retail Xstore Point of Service | =19.0.2 | |
Oracle Retail Xstore Point of Service | =20.0.1 | |
Oracle Utilities Framework | =4.2.0.2.0 | |
Oracle Utilities Framework | =4.2.0.3.0 | |
Oracle Utilities Framework | =4.3.0.1.0 | |
Oracle Utilities Framework | =4.3.0.6.0 | |
Oracle Utilities Framework | =4.4.0.0.0 | |
Oracle Utilities Framework | =4.4.0.2.0 | |
Oracle Utilities Framework | =4.4.0.3.0 | |
Oracle Utilities Testing Accelerator | =6.0.0.1.1 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
XStream XStream | ||
<1.4.18 | ||
=9.0 | ||
=10.0 | ||
=11.0 | ||
=33 | ||
=34 | ||
=35 | ||
=12.2.1.4.0 | ||
=11.3.2 | ||
=11.3 | ||
=12.0 | ||
=1.9.0 | ||
=1.10.0 | ||
=1.14.0 | ||
=7.3.4 | ||
=7.3.5 | ||
=7.4.0 | ||
=7.4.1 | ||
=7.4.2 | ||
=16.0.6 | ||
=17.0.4 | ||
=18.0.3 | ||
=19.0.2 | ||
=20.0.1 | ||
=4.2.0.2.0 | ||
=4.2.0.3.0 | ||
=4.3.0.1.0 | ||
=4.3.0.6.0 | ||
=4.4.0.0.0 | ||
=4.4.0.2.0 | ||
=4.4.0.3.0 | ||
=6.0.0.1.1 | ||
=12.2.1.3.0 | ||
=12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-39144 is a remote code execution vulnerability in XStream, a library for serializing objects to XML and back.
Any system or application that uses an affected version of XStream may be affected by CVE-2021-39144.
CVE-2021-39144 has a severity rating of 8.5, which is classified as high.
To fix CVE-2021-39144, you should update to XStream version 1.4.18 or higher.
You can find more information about CVE-2021-39144 at the following references: [link1], [link2], [link3].