VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago

CVE-2021-21345

9.9 Critical Protected by RASP

Description

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CWE-94 · Code injectionCWE-502 · Deserialization of untrusted dataCWE-78 · OS command injection

Exploitation Status

Working exploit published

A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC 1 indexed Published artifacts you can open, in Nuclei.
  • EPSS 72% chance in 30 days A model prediction, not an observation. Higher than 99% of all scored CVEs.
IndexArtifactStarsFirst seen
Nuclei XStream < 1.4.16 - Remote Code Execution

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: Manual classification assigned status: MITIGATED-BY-SECURE-RULE

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification assigned status: MITIGATED-BY-SECURE-RULE

CVSS

9.9 CRITICAL v3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H NVD Primary published
CVSS 3.1 5.8 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N security-advisories@github.com Secondary
CVSS 2.0 6.5 no band published AV:N/AC:L/Au:S/C:P/I:P/A:P NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update October 2021 CPU 2021-Q4 Oracle Communications / Policy (XStream) (12.5.0)
Oracle Financial Services Applications / Common Core (XStream) (14.2, 14.3, 14.5)
Oracle Critical Patch Update July 2021 CPU 2021-Q3 Oracle Communications Applications / CN ECE (XStream) (12.0.0.3.0)
Oracle Communications Applications / Drools Ruleset (XStream) (7.3.2, 7.3.4, 7.3.5, 7.4.0, 7.4.1)
Oracle Financial Services Applications / Collections (XStream) (2.10.0, 2.12.0)
Oracle Financial Services Applications / Collections (XStream) (2.4.0, 2.7.1, 2.9.0, 2.12.0)
Oracle Fusion Middleware / General (XStream) (11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0)
Oracle Fusion Middleware / Security Framework (XStream) (11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0)
Oracle Retail Applications / Xenvironment (XStream) (16.0.6, 17.0.4, 18.0.3, 19.0.2)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Communications Policy (XStream) 12.5.0 12.5.0
Oracle Communications Applications CN ECE (XStream) 12.0.0.3.0 12.0.0.3.0
Oracle Communications Applications Drools Ruleset (XStream) 7.3.2, 7.3.4, 7.3.5, 7.4.0, 7.4.1 7.3.2 · 7.3.4 · 7.3.5 · 7.4.0 · 7.4.1
Oracle Financial Services Applications Collections (XStream) 2.4.0, 2.7.1, 2.9.0, 2.12.0 2.4.0 · 2.7.1 · 2.9.0 · 2.10.0 · 2.12.0
Oracle Financial Services Applications Common Core (XStream) 14.2, 14.3, 14.5 14.2 · 14.3 · 14.5
Oracle Fusion Middleware General (XStream) 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0
Oracle Fusion Middleware Security Framework (XStream) 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0
Oracle Retail Applications Xenvironment (XStream) 16.0.6, 17.0.4, 18.0.3, 19.0.2 16.0.6 · 17.0.4 · 18.0.3 · 19.0.2

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
com.thoughtworks.xstream:xstream 0 1.4.16 unbounded

🖥️ Product CPEs & Version Ranges

17 product(s) over 41 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apache activemq generic < 5.15.14 · 5.16.0 · 5.16.1
nvd apache jmeter generic < 5.5
osv com.thoughtworks.xstream xstream generic < 1.4.16
nvd debian debian linux generic 9.0 · 10.0 · 11.0
nvd fedoraproject fedora generic 33 · 34 · 35
nvd netapp oncommand insight generic any version
nvd oracle banking enterprise default management generic 2.10.0 · 2.12.0
nvd oracle banking platform generic 2.4.0 · 2.7.1 · 2.9.0 · 2.12.0
nvd oracle banking virtual account management generic 14.2.0 · 14.3.0 · 14.5.0
nvd oracle business activity monitoring generic 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0
nvd oracle communications billing and revenue management elastic charging engine generic 12.0.0.3.0
nvd oracle communications policy management generic 12.5.0
nvd oracle communications unified inventory management generic 7.3.2 · 7.3.4 · 7.3.5 · 7.4.0 · 7.4.1
nvd oracle peoplesoft enterprise peopletools generic 8.58 · 8.59
nvd oracle retail xstore point of service generic 16.0.6 · 17.0.4 · 18.0.3 · 19.0.2
nvd oracle webcenter portal generic 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0
nvd xstream xstream generic < 1.4.16

Manual classification context

A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.

## Manual Classification Context **Labels:** DROOLS RULESET (XSTREAM), HTTP, SECURITY FRAMEWORK (XSTREAM), COLLECTIONS (XSTREAM), XENVIRONMENT (XSTREAM), GENERAL (XSTREAM), POLICY (XSTREAM), COMMON CORE (XSTREAM), CN ECE (XSTREAM) **Products:** ORACLE BANKING VIRTUAL ACCOUNT MANAGEMENT, ORACLE BANKING PLATFORM, ORACLE COMMUNICATIONS BRM - ELASTIC CHARGING ENGINE, ORACLE FUSION MIDDLEWARE, ORACLE WEBCENTER PORTAL, ORACLE FINANCIAL SERVICES APPLICATIONS, ORACLE RETAIL XSTORE POINT OF SERVICE, ORACLE COMMUNICATIONS, ORACLE BAM (BUSINESS ACTIVITY MONITORING), ORACLE RETAIL APPLICATIONS, ORACLE COMMUNICATIONS UNIFIED INVENTORY MANAGEMENT, ORACLE BANKING ENTERPRISE DEFAULT MANAGEMENT, ORACLE COMMUNICATIONS APPLICATIONS, ORACLE COMMUNICATIONS POLICY MANAGEMENT

References

URLTags
https://github.com/x-stream/xstream/security/advisories/GHSA-hwpc-8xqv-jvj4 WEB
https://x-stream.github.io/security.html#workaround WEB
https://x-stream.github.io/CVE-2021-21345.html WEB
https://www.oracle.com/security-alerts/cpuoct2021.html WEB
https://www.oracle.com/security-alerts/cpujan2022.html WEB
https://www.oracle.com/security-alerts/cpuApr2021.html WEB
https://www.oracle.com//security-alerts/cpujul2021.html WEB
https://www.debian.org/security/2021/dsa-5004 WEB
https://security.netapp.com/advisory/ntap-20210430-0002 WEB
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB WEB

Timeline

Published 2021-03-23 Last modified 2026-06-17
Published2021-03-23By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.