CVE-2021-39150 Details
Description
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xstream xstream | < 1.4.18 |
CPE
Remediation
| |
| fedoraproject fedora | 33 34 35 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 11.0 |
CPE
Remediation
| |
| netapp snapmanager | All versions |
CPE
Remediation
| |
| oracle business activity monitoring | 12.2.1.4.0 |
CPE
Remediation
| |
| oracle commerce guided search | 11.3.2 |
CPE
Remediation
| |
| oracle communications billing and revenue management elastic charging engine | 11.3 12.0 |
CPE
Remediation
| |
| oracle communications cloud native core automated test suite | 1.9.0 |
CPE
Remediation
| |
| oracle communications cloud native core binding support function | 1.10.0 |
CPE
Remediation
| |
| oracle communications cloud native core policy | 1.14.0 |
CPE
Remediation
| |
| oracle communications unified inventory management | 7.3.4 7.3.5 7.4.0 7.4.1 7.4.2 |
CPE
Remediation
| |
| oracle retail xstore point of service | 16.0.6 17.0.4 18.0.3 19.0.2 20.0.1 |
CPE
Remediation
| |
| oracle utilities framework | 4.2.0.2.0 4.2.0.3.0 4.3.0.1.0 4.3.0.6.0 4.4.0.0.0 4.4.0.2.0 4.4.0.3.0 |
CPE
Remediation
| |
| oracle utilities testing accelerator | 6.0.0.1.1 |
CPE
Remediation
| |
| oracle webcenter portal | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
Change History
20 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 5, 2022 | Modified Analysis | [email protected] |
| Jul 25, 2022 | CVE Modified | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Feb 16, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Nov 30, 2021 | Modified Analysis | [email protected] |
| Nov 11, 2021 | CVE Modified | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Nov 6, 2021 | Modified Analysis | [email protected] |
| Oct 30, 2021 | CVE Modified | [email protected] |
| Oct 13, 2021 | CVE Modified | [email protected] |
| Oct 7, 2021 | Modified Analysis | [email protected] |
| Sep 30, 2021 | CVE Modified | [email protected] |
| Sep 23, 2021 | CVE Modified | [email protected] |
| Aug 31, 2021 | Initial Analysis | [email protected] |