VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 45 minutes ago

CVE-2021-21347

9.8 Critical Protected by RASP

Description

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CWE-434 · Unrestricted file uploadCWE-502 · Deserialization of untrusted data

Exploitation Status

No public exploit

Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 5 years.

CVSS E:U

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC none indexed
  • EPSS 14% chance in 30 days A model prediction, not an observation. Higher than 96% of all scored CVEs.

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR XXE rule.

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review human manual-review
  • Record active
Decided by manual-classification : A researcher's recorded decision for this specific CVE
Finding A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR XXE rule.

Waratek research note

written 2026-09-14

Written by a Waratek engineer reviewing this CVE. A written classification sets the status directly, ahead of every automated scope rule except a withdrawal.

Comments

Rule Name: XXE rule

CVSS

9.8 CRITICAL v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H NVD Primary published
CVSS 3.1 6.1 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N security-advisories@github.com Secondary
CVSS 2.0 7.5 no band published AV:N/AC:L/Au:N/C:P/I:P/A:P NVD Primary

Affected Software & Releases

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
com.thoughtworks.xstream:xstream 0 1.4.16 unbounded

🖥️ Product CPEs & Version Ranges

17 product(s) over 43 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apache activemq generic < 5.15.14 · 5.16.0 · 5.16.1
nvd apache jmeter generic < 5.5
osv com.thoughtworks.xstream xstream generic < 1.4.16
nvd debian debian linux generic 9.0 · 10.0 · 11.0
nvd fedoraproject fedora generic 33 · 34 · 35
nvd netapp oncommand insight generic any version
nvd oracle banking enterprise default management generic 2.10.0 · 2.12.0
nvd oracle banking platform generic 2.4.0 · 2.7.1 · 2.9.0 · 2.12.0
nvd oracle banking virtual account management generic 14.2.0 · 14.3.0 · 14.5.0
nvd oracle business activity monitoring generic 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0
nvd oracle communications billing and revenue management elastic charging engine generic 12.0.0.3.0
nvd oracle communications policy management generic 12.5.0
nvd oracle communications unified inventory management generic 7.3.2 · 7.3.4 · 7.3.5 · 7.4.0 · 7.4.1
nvd oracle retail xstore point of service generic 16.0.6 · 17.0.4 · 18.0.3 · 19.0.2
nvd oracle webcenter portal generic 11.1.1.9.0 · 12.2.1.3.0 · 12.2.1.4.0
nvd oracle weblogic server generic 12.1.3.0.0 · 12.2.1.3.0 · 12.2.1.4.0 · 14.1.1.0.0
nvd xstream xstream generic < 1.4.16

References

URLTags
https://github.com/x-stream/xstream/security/advisories/GHSA-qpfq-ph7r-qv6f WEB
https://github.com/x-stream/xstream PACKAGE
https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd@%3Cusers.activemq.apache.org%3E WEB
https://lists.apache.org/thread.html/r9ac71b047767205aa22e3a08cb33f3e0586de6b2fac48b425c6e16b0@%3Cdev.jmeter.apache.org%3E WEB
https://lists.debian.org/debian-lts-announce/2021/04/msg00002.html WEB
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP WEB
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7 WEB
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB WEB
https://security.netapp.com/advisory/ntap-20210430-0002 WEB
https://www.debian.org/security/2021/dsa-5004 WEB

Timeline

Published 2021-03-23 Last modified 2026-06-17
Published2021-03-23By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.
Classification created2026-09-14First commit adding this CVE's research note.
Last VRT activity2026-09-14Most recent commit touching this CVE's classification, patch or rule file.