Severity
9.8CRITICAL
EPSS
93.0%
top 0.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateJan 15

Description

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages13 packages

Mavencom.thoughtworks.xstream:xstream1.4.101.4.11
Debianlibxstream-java< 1.4.11-1+3
NVDoracle/utilities_framework4.3.0.1.04.3.0.6.0+4
CVEListV5xstream/xstreamfixed in 1.4.11
NVDxstream/xstream1.4.10

Patches

🔴Vulnerability Details

4
GHSA
Deserialization of Untrusted Data and Code Injection in xstream2019-07-26
OSV
Deserialization of Untrusted Data and Code Injection in xstream2019-07-26
CVEList
CVE-2019-10173: It was found that xstream API version 12019-07-23
OSV
CVE-2019-10173: It was found that xstream API version 12019-07-23

📋Vendor Advisories

5
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Xstream) — CVE-2019-101732021-01-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Diameter Gateway and SDK (xstream) — CVE-2019-101732020-10-15
Oracle
Oracle Oracle Retail Applications Risk Matrix: Point of Sale (xstream) — CVE-2019-101732020-04-15
Debian
CVE-2019-10173: libxstream-java - It was found that xstream API version 1.4.10 before 1.4.11 introduced a regressi...2019
Red Hat
xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)2018-10-23

💬Community

1
Bugzilla
CVE-2019-10173 xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)2019-06-21
CVE-2019-10173 (CRITICAL CVSS 9.8) | It was found that xstream API versi | cvebase.io