// For flags

CVE-2019-10173

xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

Se encontró que la API de xstream versión 1.4.10 anterior a 1.4.11, introdujo una regresión para un fallo de deserialización anterior. Si el framework security no ha sido inicializado, puede permitir a un atacante remoto ejecutar comandos de shell arbitrarios cuando se deserializa un XML o cualquier formato compatible. p.ej. JSON. (Regresión de CVE-2013-7285)

It was found that xstream API version 1.4.10 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. This a regression of CVE-2013-7285 fixed in 1.4.7 (fixed) as of BPMS 6.0.1, the regression was introduced with xstream-1.4.10 implemented in RHPAM.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-03-27 CVE Reserved
  • 2019-07-22 CVE Published
  • 2024-07-16 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
  • CWE-502: Deserialization of Untrusted Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xstream Project
Search vendor "Xstream Project"
Xstream
Search vendor "Xstream Project" for product "Xstream"
1.4.10
Search vendor "Xstream Project" for product "Xstream" and version "1.4.10"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
>= 2.4.0 <= 2.10.0
Search vendor "Oracle" for product "Banking Platform" and version " >= 2.4.0 <= 2.10.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.4.0
Search vendor "Oracle" for product "Banking Platform" and version "2.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.7.1
Search vendor "Oracle" for product "Banking Platform" and version "2.7.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Platform
Search vendor "Oracle" for product "Banking Platform"
2.9.0
Search vendor "Oracle" for product "Banking Platform" and version "2.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Business Activity Monitoring
Search vendor "Oracle" for product "Business Activity Monitoring"
11.1.1.9.0
Search vendor "Oracle" for product "Business Activity Monitoring" and version "11.1.1.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Business Activity Monitoring
Search vendor "Oracle" for product "Business Activity Monitoring"
12.2.1.3.0
Search vendor "Oracle" for product "Business Activity Monitoring" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Business Activity Monitoring
Search vendor "Oracle" for product "Business Activity Monitoring"
12.2.1.4.0
Search vendor "Oracle" for product "Business Activity Monitoring" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Billing And Revenue Management Elastic Charging Engine
Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine"
11.3.0.9.0
Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine" and version "11.3.0.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Billing And Revenue Management Elastic Charging Engine
Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine"
12.0.0.3.0
Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine" and version "12.0.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
>= 8.0.0 <= 8.2.2
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0 <= 8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.3.0
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Unified Inventory Management
Search vendor "Oracle" for product "Communications Unified Inventory Management"
7.4.0
Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Endeca Information Discovery Studio
Search vendor "Oracle" for product "Endeca Information Discovery Studio"
3.2.0
Search vendor "Oracle" for product "Endeca Information Discovery Studio" and version "3.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Endeca Information Discovery Studio
Search vendor "Oracle" for product "Endeca Information Discovery Studio"
3.2.0.0
Search vendor "Oracle" for product "Endeca Information Discovery Studio" and version "3.2.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Xstore Point Of Service
Search vendor "Oracle" for product "Retail Xstore Point Of Service"
17.0
Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "17.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
>= 4.3.0.1.0 <= 4.3.0.6.0
Search vendor "Oracle" for product "Utilities Framework" and version " >= 4.3.0.1.0 <= 4.3.0.6.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
2.2.0.0.0
Search vendor "Oracle" for product "Utilities Framework" and version "2.2.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.2.0.2.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.2.0.3.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Utilities Framework
Search vendor "Oracle" for product "Utilities Framework"
4.4.0.0.0
Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
11.1.1.9.0
Search vendor "Oracle" for product "Webcenter Portal" and version "11.1.1.9.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.3.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.4.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.4.0"
-
Affected