CVE-2019-10173
Severity
9.8CRITICAL
EPSS
93.0%
top 0.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateJan 15
Description
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages13 packages
Patches
🔴Vulnerability Details
4📋Vendor Advisories
5Oracle▶
Oracle Oracle Communications Applications Risk Matrix: Diameter Gateway and SDK (xstream) — CVE-2019-10173↗2020-10-15
Oracle
▶
Debian▶
CVE-2019-10173: libxstream-java - It was found that xstream API version 1.4.10 before 1.4.11 introduced a regressi...↗2019
Red Hat▶
xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)↗2018-10-23
💬Community
1Bugzilla▶
CVE-2019-10173 xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)↗2019-06-21