CVE-2021-39150
23.08.2021, 19:15
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.Enginsight
Vendor | Product | Version |
---|---|---|
xstream | xstream | 𝑥 < 1.4.18 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
netapp | snapmanager | - |
netapp | snapmanager | - |
oracle | business_activity_monitoring | 12.2.1.4.0 |
oracle | commerce_guided_search | 11.3.2 |
oracle | communications_billing_and_revenue_management_elastic_charging_engine | 11.3 |
oracle | communications_billing_and_revenue_management_elastic_charging_engine | 12.0 |
oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 |
oracle | communications_cloud_native_core_binding_support_function | 1.10.0 |
oracle | communications_cloud_native_core_policy | 1.14.0 |
oracle | communications_unified_inventory_management | 7.3.4 |
oracle | communications_unified_inventory_management | 7.3.5 |
oracle | communications_unified_inventory_management | 7.4.0 |
oracle | communications_unified_inventory_management | 7.4.1 |
oracle | communications_unified_inventory_management | 7.4.2 |
oracle | retail_xstore_point_of_service | 16.0.6 |
oracle | retail_xstore_point_of_service | 17.0.4 |
oracle | retail_xstore_point_of_service | 18.0.3 |
oracle | retail_xstore_point_of_service | 19.0.2 |
oracle | retail_xstore_point_of_service | 20.0.1 |
oracle | utilities_framework | 4.2.0.2.0 |
oracle | utilities_framework | 4.2.0.3.0 |
oracle | utilities_framework | 4.3.0.1.0 |
oracle | utilities_framework | 4.3.0.6.0 |
oracle | utilities_framework | 4.4.0.0.0 |
oracle | utilities_framework | 4.4.0.2.0 |
oracle | utilities_framework | 4.4.0.3.0 |
oracle | utilities_testing_accelerator | 6.0.0.1.1 |
oracle | webcenter_portal | 12.2.1.3.0 |
oracle | webcenter_portal | 12.2.1.4.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References