CVE-2013-7285
15.05.2019, 17:29
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Vendor | Product | Version |
---|---|---|
oracle | endeca_information_discovery_studio | 3.2.0 |
apache | activemq | 5.15.8 |
xstream | xstream | 𝑥 ≤ 1.4.6 |
xstream | xstream | 1.4.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References