cbcvebase.
CVE-2013-7285
published 2019-05-15

CVE-2013-7285: Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
apacheactivemq
debianlibxstream-java< libxstream-java 1.4.7-1 (bookworm)libxstream-java 1.4.7-1 (bookworm)
debianlibxstream-java< libxstream-java 1.4.11-1 (bookworm)libxstream-java 1.4.11-1 (bookworm)
jenkinsjenkins_core
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform2.4.0 – 2.10.0
oraclebusiness_activity_monitoring
oraclebusiness_activity_monitoring
oraclebusiness_activity_monitoring
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
oraclecommunications_diameter_signaling_router8.0.0 – 8.2.2
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracleendeca_information_discovery_studio
oracleendeca_information_discovery_studio
oracleretail_xstore_point_of_service
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework4.3.0.1.0 – 4.3.0.6.0
oraclewebcenter_portal

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL