imPC@ndo EN

Tracker / CVE-2021-21347

CVE-2021-21347

Media 6.1

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

Prodotti e versioni affette

apache activemq
apache activemq · … → 5.15.14
apache jmeter · … → 5.5
debian debian_linux
fedoraproject fedora
netapp oncommand_insight
oracle banking_enterprise_default_management
oracle banking_platform
oracle banking_virtual_account_management
oracle business_activity_monitoring
oracle communications_billing_and_revenue_management_elastic_charging_engine
oracle communications_policy_management
oracle communications_unified_inventory_management
oracle retail_xstore_point_of_service
oracle webcenter_portal
oracle weblogic_server
xstream xstream · … → 1.4.16

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti