HIGH✓ PATCH🇬🇧 English

CVE-2020-26217

CVSS 8.0v3.1pub. 2020-11-16upd. 2025-05-23

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Apache Activemq

    APP
    Apache
    5.16.0< 5.15.14
  • Debian

    OS
    Debian
    10.09.0
  • Netapp Snapmanager

    APP
    Netapp
    wszystkie wersje
  • Oracle Banking Cash Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Corporate Lending Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Credit Facilities Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Platform

    APP
    Oracle
    2.4.02.7.12.9.0
  • Oracle Banking Supply Chain Finance

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Trade Finance Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Virtual Account Management

    APP
    Oracle
    14.2.014.3.014.5.0
  • Oracle Business Activity Monitoring

    APP
    Oracle
    11.1.1.9.012.2.1.3.012.2.1.4.0
  • Oracle Communications Policy Management

    APP
    Oracle
    12.5.0
  • Oracle Endeca Information Discovery Studio

    APP
    Oracle
    3.2.0.0
  • Oracle Retail Xstore Point Of Service

    APP
    Oracle
    16.0.617.0.418.0.319.0.2
  • Xstream

    APP
    Xstream
    < 1.4.14
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
RCECommand Injection
CWE
Referencje

Powiązane podatności

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓ten sam produkt

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓ten sam produkt

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓ten sam produkt

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki