Vulnerabilities > CVE-2019-10173

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
xstream-project
oracle
critical

Summary

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

Vulnerable Configurations

Part Description Count
Application
Xstream_Project
1
Application
Oracle
41

Redhat

advisories
  • rhsa
    idRHSA-2019:3892
  • rhsa
    idRHSA-2019:4352
  • rhsa
    idRHSA-2020:0445
  • rhsa
    idRHSA-2020:0727