CVE-2021-21345XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
CWE-94 · Code injectionCWE-502 · Deserialization of untrusted dataCWE-78 · OS command injection
Working exploit published
A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.
CVSS E:P
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| Nuclei | XStream < 1.4.16 - Remote Code Execution |
A Waratek agent blocks this today.
Applicable rule: Manual classification assigned status: MITIGATED-BY-SECURE-RULE
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification assigned status: MITIGATED-BY-SECURE-RULE |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
3 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
NVD | Primary | published |
| CVSS 3.1 | 5.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N |
security-advisories@github.com | Secondary | |
| CVSS 2.0 | 6.5 | no band published | AV:N/AC:L/Au:S/C:P/I:P/A:P |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update October 2021 ↗ | CPU | 2021-Q4 | Oracle Communications / Policy (XStream) (12.5.0) Oracle Financial Services Applications / Common Core (XStream) (14.2, 14.3, 14.5) |
| Oracle Critical Patch Update July 2021 ↗ | CPU | 2021-Q3 | Oracle Communications Applications / CN ECE (XStream) (12.0.0.3.0) Oracle Communications Applications / Drools Ruleset (XStream) (7.3.2, 7.3.4, 7.3.5, 7.4.0, 7.4.1) Oracle Financial Services Applications / Collections (XStream) (2.10.0, 2.12.0) Oracle Financial Services Applications / Collections (XStream) (2.4.0, 2.7.1, 2.9.0, 2.12.0) Oracle Fusion Middleware / General (XStream) (11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0) Oracle Fusion Middleware / Security Framework (XStream) (11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0) Oracle Retail Applications / Xenvironment (XStream) (16.0.6, 17.0.4, 18.0.3, 19.0.2) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Communications | Policy (XStream) | 12.5.0 | 12.5.0 |
| Oracle Communications Applications | CN ECE (XStream) | 12.0.0.3.0 | 12.0.0.3.0 |
| Oracle Communications Applications | Drools Ruleset (XStream) | 7.3.2, 7.3.4, 7.3.5, 7.4.0, 7.4.1 | 7.3.2 · 7.3.4 · 7.3.5 · 7.4.0 · 7.4.1 |
| Oracle Financial Services Applications | Collections (XStream) | 2.4.0, 2.7.1, 2.9.0, 2.12.0 | 2.4.0 · 2.7.1 · 2.9.0 · 2.10.0 · 2.12.0 |
| Oracle Financial Services Applications | Common Core (XStream) | 14.2, 14.3, 14.5 | 14.2 · 14.3 · 14.5 |
| Oracle Fusion Middleware | General (XStream) | 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 | 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0 |
| Oracle Fusion Middleware | Security Framework (XStream) | 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 | 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0 |
| Oracle Retail Applications | Xenvironment (XStream) | 16.0.6, 17.0.4, 18.0.3, 19.0.2 | 16.0.6 · 17.0.4 · 18.0.3 · 19.0.2 |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
com.thoughtworks.xstream:xstream |
0 | 1.4.16 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apache | activemq | generic | < 5.15.14 · 5.16.0 · 5.16.1 |
| nvd | apache | jmeter | generic | < 5.5 |
| osv | com.thoughtworks.xstream | xstream | generic | < 1.4.16 |
| nvd | debian | debian linux | generic | 9.0 · 10.0 · 11.0 |
| nvd | fedoraproject | fedora | generic | 33 · 34 · 35 |
| nvd | netapp | oncommand insight | generic | any version |
| nvd | oracle | banking enterprise default management | generic | 2.10.0 · 2.12.0 |
| nvd | oracle | banking platform | generic | 2.4.0 · 2.7.1 · 2.9.0 · 2.12.0 |
| nvd | oracle | banking virtual account management | generic | 14.2.0 · 14.3.0 · 14.5.0 |
| nvd | oracle | business activity monitoring | generic | 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0 |
| nvd | oracle | communications billing and revenue management elastic charging engine | generic | 12.0.0.3.0 |
| nvd | oracle | communications policy management | generic | 12.5.0 |
| nvd | oracle | communications unified inventory management | generic | 7.3.2 · 7.3.4 · 7.3.5 · 7.4.0 · 7.4.1 |
| nvd | oracle | peoplesoft enterprise peopletools | generic | 8.58 · 8.59 |
| nvd | oracle | retail xstore point of service | generic | 16.0.6 · 17.0.4 · 18.0.3 · 19.0.2 |
| nvd | oracle | webcenter portal | generic | 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0 |
| nvd | xstream | xstream | generic | < 1.4.16 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** DROOLS RULESET (XSTREAM), HTTP, SECURITY FRAMEWORK (XSTREAM), COLLECTIONS (XSTREAM), XENVIRONMENT (XSTREAM), GENERAL (XSTREAM), POLICY (XSTREAM), COMMON CORE (XSTREAM), CN ECE (XSTREAM) **Products:** ORACLE BANKING VIRTUAL ACCOUNT MANAGEMENT, ORACLE BANKING PLATFORM, ORACLE COMMUNICATIONS BRM - ELASTIC CHARGING ENGINE, ORACLE FUSION MIDDLEWARE, ORACLE WEBCENTER PORTAL, ORACLE FINANCIAL SERVICES APPLICATIONS, ORACLE RETAIL XSTORE POINT OF SERVICE, ORACLE COMMUNICATIONS, ORACLE BAM (BUSINESS ACTIVITY MONITORING), ORACLE RETAIL APPLICATIONS, ORACLE COMMUNICATIONS UNIFIED INVENTORY MANAGEMENT, ORACLE BANKING ENTERPRISE DEFAULT MANAGEMENT, ORACLE COMMUNICATIONS APPLICATIONS, ORACLE COMMUNICATIONS POLICY MANAGEMENT
| Published | 2021-03-23 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |