Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 98.1%; technical severity is CVSS 8.5.
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Who should care
- Teams operating Debian Linux, Fedora, Snapmanager +12 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Debian Linux, Fedora, Snapmanager +12 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Oracle Security patch Cpuapr2022
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
Upgrade
- Lists Fedoraproject Security release notes 22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHPLists FedoraprojectVerification pending ↗
- Lists Fedoraproject Security release notes PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7Lists FedoraprojectVerification pending ↗
- Lists Fedoraproject Security release notes QGXIU3YDPG6OGTDHMBLAFN7BPBERXREBLists FedoraprojectVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE
- CWE-94
- Affected versions
- Debian Debian Linux (Version 9.0 | Version 10.0 | Version 11.0); Fedoraproject Fedora (Version 33 | Version 34 | Version 35); Netapp Snapmanager (Version - | Version -); Oracle Business Activity Monitoring (Version 12.2.1.4.0); Oracle Commerce Guided Search (Version 11.3.2); Oracle Communications Billing And Revenue Management Elastic Charging Engine (Version 11.3 | Version 12.0); Oracle Communications Cloud Native Core Automated Test Suite (Version 1.9.0); Oracle Communications Cloud Native Core Binding Support Function (Version 1.10.0)
- Fixed versions
- Xstream Xstream (Fixed from 1.4.18)
- Published
- 23 August 2021
- Attack vector
- Network
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 98.1%
- Signal calculated at 83