HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2020-26217

CVSS 8.0v3.1pub. 2020-11-16upd. 2025-05-23

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Apache Activemq

    APP
    Apache
    5.16.0< 5.15.14
  • Debian

    OS
    Debian
    10.09.0
  • Netapp Snapmanager

    APP
    Netapp
    all versions
  • Oracle Banking Cash Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Corporate Lending Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Credit Facilities Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Platform

    APP
    Oracle
    2.4.02.7.12.9.0
  • Oracle Banking Supply Chain Finance

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Trade Finance Process Management

    APP
    Oracle
    14.214.314.5
  • Oracle Banking Virtual Account Management

    APP
    Oracle
    14.2.014.3.014.5.0
  • Oracle Business Activity Monitoring

    APP
    Oracle
    11.1.1.9.012.2.1.3.012.2.1.4.0
  • Oracle Communications Policy Management

    APP
    Oracle
    12.5.0
  • Oracle Endeca Information Discovery Studio

    APP
    Oracle
    3.2.0.0
  • Oracle Retail Xstore Point Of Service

    APP
    Oracle
    16.0.617.0.418.0.319.0.2
  • Xstream

    APP
    Xstream
    < 1.4.14
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki