CVE-2020-26217 Details
Description
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xstream xstream | < 1.4.14 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 |
CPE
Remediation
| |
| netapp snapmanager | All versions |
CPE
Remediation
| |
| apache activemq | < 5.15.14 5.16.0 |
CPE
Remediation
| |
| oracle banking cash management | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking corporate lending process management | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking credit facilities process management | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking platform | 2.4.0 2.7.1 2.9.0 |
CPE
Remediation
| |
| oracle banking supply chain finance | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking trade finance process management | 14.2 14.3 14.5 |
CPE
Remediation
| |
| oracle banking virtual account management | 14.2.0 14.3.0 14.5.0 |
CPE
Remediation
| |
| oracle business activity monitoring | 11.1.1.9.0 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle communications policy management | 12.5.0 |
CPE
Remediation
| |
| oracle endeca information discovery studio | 3.2.0.0 |
CPE
Remediation
| |
| oracle retail xstore point of service | 16.0.6 17.0.4 18.0.3 19.0.2 |
CPE
Remediation
| |
Change History
24 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 28, 2022 | Reanalysis | [email protected] |
| May 12, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Mar 1, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Dec 3, 2021 | Modified Analysis | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Oct 6, 2021 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| Apr 13, 2021 | Modified Analysis | [email protected] |
| Apr 9, 2021 | CVE Modified | [email protected] |
| Jan 4, 2021 | CVE Modified | [email protected] |
| Dec 30, 2020 | CVE Modified | [email protected] |
| Dec 30, 2020 | CVE Modified | [email protected] |
| Dec 16, 2020 | CVE Modified | [email protected] |
| Dec 1, 2020 | Initial Analysis | [email protected] |
| Dec 1, 2020 | CVE Modified | [email protected] |
| Nov 16, 2020 | CVE Modified | [email protected] |