CVE-2021-29505

HIGHCVSS 8.8/10EPSS 77.73%

Last modified

CVE-2021-29505 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. EPSS estimates a 77.73% chance of exploitation in the next 30 days.

Description

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
77.73%

99.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
XstreamXstream< 1.4.17
DebianDebian Linux9.0
DebianDebian Linux10.0
DebianDebian Linux11.0
FedoraprojectFedora33
FedoraprojectFedora34
FedoraprojectFedora35
NetappSnapmanagerAll versions
OracleBanking Cash Management14.2
OracleBanking Cash Management14.3
OracleBanking Cash Management14.5
OracleBanking Corporate Lending Process Management14.2.0
OracleBanking Corporate Lending Process Management14.3.0
OracleBanking Corporate Lending Process Management14.5.0
OracleBanking Credit Facilities Process Management14.2.0
OracleBanking Credit Facilities Process Management14.3.0
OracleBanking Credit Facilities Process Management14.5.0
OracleBanking Supply Chain Finance14.2.0
OracleBanking Trade Finance Process Management14.5.0
OracleBusiness Activity Monitoring11.1.1.9.0
OracleBusiness Activity Monitoring12.2.1.3.0
OracleBusiness Activity Monitoring12.2.1.4.0
OracleCommunications Brm - Elastic Charging Engine11.3
OracleCommunications Brm - Elastic Charging Engine12.0
OracleCommunications Unified Inventory Management7.3.4
OracleCommunications Unified Inventory Management7.3.5
OracleCommunications Unified Inventory Management7.4.0
OracleCommunications Unified Inventory Management7.4.1
OracleCommunications Unified Inventory Management7.4.2
OracleEnterprise Manager Ops Center12.4.0.0
OracleRetail Customer Insights15.0.2
OracleRetail Customer Insights16.0.2
OracleRetail Xstore Point Of Service16.0.6
OracleRetail Xstore Point Of Service17.0.4
OracleRetail Xstore Point Of Service18.0.3
OracleRetail Xstore Point Of Service19.0.2
OracleRetail Xstore Point Of Service20.0.1
OracleWebcenter Portal12.2.1.3.0
OracleWebcenter Portal12.2.1.4.0
OracleWebcenter Sites12.2.1.3.0
OracleWebcenter Sites12.2.1.4.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-29505?
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.
How severe is CVE-2021-29505?
CVE-2021-29505 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 77.73% probability of exploitation in the next 30 days.
How do I fix CVE-2021-29505?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-29505?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST