CVE-2019-10173
xstream: remote code execution due to insecure XML deserialization (regression of CVE-2013-7285)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Se encontró que la API de xstream versión 1.4.10 anterior a 1.4.11, introdujo una regresión para un fallo de deserialización anterior. Si el framework security no ha sido inicializado, puede permitir a un atacante remoto ejecutar comandos de shell arbitrarios cuando se deserializa un XML o cualquier formato compatible. p.ej. JSON. (Regresión de CVE-2013-7285)
It was found that xstream API version 1.4.10 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. This a regression of CVE-2013-7285 fixed in 1.4.7 (fixed) as of BPMS 6.0.1, the regression was introduced with xstream-1.4.10 implemented in RHPAM.
Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. This release of Red Hat Decision Manager 7.4.0 serves as an update to Red Hat Decision Manager 7.3.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include code execution and deserialization vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-27 CVE Reserved
- 2019-07-22 CVE Published
- 2024-08-04 CVE Updated
- 2025-07-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://x-stream.github.io/changes.html#1.4.11 | Release Notes | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10173 | Issue Tracking | |
https://www.oracle.com/security-alerts/cpuapr2020.html | Third Party Advisory |
|
https://www.oracle.com/security-alerts/cpujan2021.html | Third Party Advisory |
|
https://www.oracle.com/security-alerts/cpuoct2020.html | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.oracle.com//security-alerts/cpujul2021.html | 2022-10-05 | |
https://www.oracle.com/security-alerts/cpuApr2021.html | 2022-10-05 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:3892 | 2022-10-05 | |
https://access.redhat.com/errata/RHSA-2019:4352 | 2022-10-05 | |
https://access.redhat.com/errata/RHSA-2020:0445 | 2022-10-05 | |
https://access.redhat.com/errata/RHSA-2020:0727 | 2022-10-05 | |
https://access.redhat.com/security/cve/CVE-2019-10173 | 2020-03-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1722971 | 2020-03-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xstream Project Search vendor "Xstream Project" | Xstream Search vendor "Xstream Project" for product "Xstream" | 1.4.10 Search vendor "Xstream Project" for product "Xstream" and version "1.4.10" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Banking Platform Search vendor "Oracle" for product "Banking Platform" | >= 2.4.0 <= 2.10.0 Search vendor "Oracle" for product "Banking Platform" and version " >= 2.4.0 <= 2.10.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Banking Platform Search vendor "Oracle" for product "Banking Platform" | 2.4.0 Search vendor "Oracle" for product "Banking Platform" and version "2.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Banking Platform Search vendor "Oracle" for product "Banking Platform" | 2.7.1 Search vendor "Oracle" for product "Banking Platform" and version "2.7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Banking Platform Search vendor "Oracle" for product "Banking Platform" | 2.9.0 Search vendor "Oracle" for product "Banking Platform" and version "2.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Activity Monitoring Search vendor "Oracle" for product "Business Activity Monitoring" | 11.1.1.9.0 Search vendor "Oracle" for product "Business Activity Monitoring" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Activity Monitoring Search vendor "Oracle" for product "Business Activity Monitoring" | 12.2.1.3.0 Search vendor "Oracle" for product "Business Activity Monitoring" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Business Activity Monitoring Search vendor "Oracle" for product "Business Activity Monitoring" | 12.2.1.4.0 Search vendor "Oracle" for product "Business Activity Monitoring" and version "12.2.1.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Billing And Revenue Management Elastic Charging Engine Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine" | 11.3.0.9.0 Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine" and version "11.3.0.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Billing And Revenue Management Elastic Charging Engine Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine" | 12.0.0.3.0 Search vendor "Oracle" for product "Communications Billing And Revenue Management Elastic Charging Engine" and version "12.0.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Signaling Router Search vendor "Oracle" for product "Communications Diameter Signaling Router" | >= 8.0.0 <= 8.2.2 Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0 <= 8.2.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.3.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Unified Inventory Management Search vendor "Oracle" for product "Communications Unified Inventory Management" | 7.4.0 Search vendor "Oracle" for product "Communications Unified Inventory Management" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Studio Search vendor "Oracle" for product "Endeca Information Discovery Studio" | 3.2.0 Search vendor "Oracle" for product "Endeca Information Discovery Studio" and version "3.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Endeca Information Discovery Studio Search vendor "Oracle" for product "Endeca Information Discovery Studio" | 3.2.0.0 Search vendor "Oracle" for product "Endeca Information Discovery Studio" and version "3.2.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Xstore Point Of Service Search vendor "Oracle" for product "Retail Xstore Point Of Service" | 17.0 Search vendor "Oracle" for product "Retail Xstore Point Of Service" and version "17.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | >= 4.3.0.1.0 <= 4.3.0.6.0 Search vendor "Oracle" for product "Utilities Framework" and version " >= 4.3.0.1.0 <= 4.3.0.6.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 2.2.0.0.0 Search vendor "Oracle" for product "Utilities Framework" and version "2.2.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.2.0.2.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.2.0.3.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.2.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Utilities Framework Search vendor "Oracle" for product "Utilities Framework" | 4.4.0.0.0 Search vendor "Oracle" for product "Utilities Framework" and version "4.4.0.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Webcenter Portal Search vendor "Oracle" for product "Webcenter Portal" | 11.1.1.9.0 Search vendor "Oracle" for product "Webcenter Portal" and version "11.1.1.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Webcenter Portal Search vendor "Oracle" for product "Webcenter Portal" | 12.2.1.3.0 Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Webcenter Portal Search vendor "Oracle" for product "Webcenter Portal" | 12.2.1.4.0 Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.4.0" | - |
Affected
|