First published: Thu Mar 13 2014(Updated: )
XStream is a simple library to serialize and de-serialize objects to and<br>from XML.<br>It was found that XStream could deserialize arbitrary user-supplied XML<br>content, representing objects of any type. A remote attacker able to pass<br>XML to XStream could use this flaw to perform a variety of attacks,<br>including remote code execution in the context of the server running the<br>XStream application. (CVE-2013-7285)<br>The main distribution of Red Hat JBoss Data Virtualization 6.0.0 does not<br>contain the vulnerable XStream library and is not vulnerable to<br>CVE-2013-7285. Only users of Red Hat JBoss Data Virtualization 6.0.0 who<br>installed an optional S-RAMP distribution as provided from the Red Hat<br>Customer Portal are advised to apply this update.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.