CVE-2020-26217

HIGHCVSS 8.8/10EPSS 85.00%

Last modified

CVE-2020-26217 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. EPSS estimates a 85.00% chance of exploitation in the next 30 days.

Description

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
85.00%

99.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
XstreamXstream< 1.4.14
DebianDebian Linux9.0
DebianDebian Linux10.0
NetappSnapmanagerAll versions
ApacheActivemq< 5.15.14
ApacheActivemq5.16.0
OracleBanking Cash Management14.2
OracleBanking Cash Management14.3
OracleBanking Cash Management14.5
OracleBanking Corporate Lending Process Management14.2
OracleBanking Corporate Lending Process Management14.3
OracleBanking Corporate Lending Process Management14.5
OracleBanking Credit Facilities Process Management14.2
OracleBanking Credit Facilities Process Management14.3
OracleBanking Credit Facilities Process Management14.5
OracleBanking Platform2.4.0
OracleBanking Platform2.7.1
OracleBanking Platform2.9.0
OracleBanking Supply Chain Finance14.2
OracleBanking Supply Chain Finance14.3
OracleBanking Supply Chain Finance14.5
OracleBanking Trade Finance Process Management14.2
OracleBanking Trade Finance Process Management14.3
OracleBanking Trade Finance Process Management14.5
OracleBanking Virtual Account Management14.2.0
OracleBanking Virtual Account Management14.3.0
OracleBanking Virtual Account Management14.5.0
OracleBusiness Activity Monitoring11.1.1.9.0
OracleBusiness Activity Monitoring12.2.1.3.0
OracleBusiness Activity Monitoring12.2.1.4.0
OracleCommunications Policy Management12.5.0
OracleEndeca Information Discovery Studio3.2.0.0
OracleRetail Xstore Point Of Service16.0.6
OracleRetail Xstore Point Of Service17.0.4
OracleRetail Xstore Point Of Service18.0.3
OracleRetail Xstore Point Of Service19.0.2

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2020-26217?
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
How severe is CVE-2020-26217?
CVE-2020-26217 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 85.00% probability of exploitation in the next 30 days.
How do I fix CVE-2020-26217?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-26217?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST