Tracker / CVE-2021-21346
CVE-2021-21346
Media 6.1
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
Prodotti e versioni affette
| apache | activemq |
|---|---|
| apache | activemq · … → 5.15.14 |
| apache | jmeter · … → 5.5 |
| debian | debian_linux |
| fedoraproject | fedora |
| netapp | oncommand_insight |
| oracle | banking_enterprise_default_management |
| oracle | banking_platform |
| oracle | banking_virtual_account_management |
| oracle | bi_publisher |
| oracle | business_activity_monitoring |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine |
| oracle | communications_policy_management |
| oracle | communications_unified_inventory_management |
| oracle | retail_xstore_point_of_service |
| oracle | webcenter_portal |
| xstream | xstream · … → 1.4.16 |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.