CVE-2021-21343 Details
Description
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in the deletion of a file on the local host. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| netapp oncommand insight | All versions |
CPE
Remediation
| |
| apache activemq | < 5.15.14 5.16.0 5.16.1 |
CPE
Remediation
| |
| apache jmeter | < 5.5 |
CPE
Remediation
| |
| xstream xstream | < 1.4.16 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 11.0 |
CPE
Remediation
| |
| fedoraproject fedora | 33 34 35 |
CPE
Remediation
| |
| oracle banking enterprise default management | 2.10.0 2.12.0 |
CPE
Remediation
| |
| oracle banking platform | 2.4.0 2.7.1 2.9.0 2.12.0 |
CPE
Remediation
| |
| oracle banking virtual account management | 14.2.0 14.3.0 14.5.0 |
CPE
Remediation
| |
| oracle business activity monitoring | 11.1.1.9.0 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle communications billing and revenue management elastic charging engine | 12.0.0.3.0 |
CPE
Remediation
| |
| oracle communications policy management | 12.5.0 |
CPE
Remediation
| |
| oracle communications unified inventory management | 7.3.2 7.3.4 7.3.5 7.4.0 7.4.1 |
CPE
Remediation
| |
| oracle retail xstore point of service | 16.0.6 17.0.4 18.0.3 19.0.2 |
CPE
Remediation
| |
| oracle webcenter portal | 11.1.1.9.0 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
Change History
21 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Feb 16, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Nov 30, 2021 | Modified Analysis | [email protected] |
| Nov 11, 2021 | CVE Modified | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Oct 30, 2021 | CVE Modified | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Oct 13, 2021 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Apr 30, 2021 | Modified Analysis | [email protected] |
| Apr 30, 2021 | CVE Modified | [email protected] |
| Apr 27, 2021 | Modified Analysis | [email protected] |
| Apr 27, 2021 | CVE Modified | [email protected] |
| Apr 6, 2021 | CVE Modified | [email protected] |
| Apr 3, 2021 | CVE Modified | [email protected] |
| Mar 25, 2021 | Initial Analysis | [email protected] |