← לוח פגיעויות

CVE-2021-39144

גבוהה 8.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
XStream Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

מדדים

CVSS 3.1
8.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
98% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-94, CWE-502, CWE-306

מוצרים מושפעים

xstream: xstream; debian: debian linux; fedoraproject: fedora; netapp: snapmanager; oracle: business activity monitoring; oracle: commerce guided search; oracle: communications billing and revenue management elastic charging engine; oracle: communications cloud native core automated test suite; oracle: communications cloud native core binding support function; oracle: communications cloud native core policy; oracle: communications unified inventory management; oracle: retail xstore point of service; oracle: utilities framework; oracle: utilities testing accelerator; oracle: webcenter portal

קישורים