XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HDebian
OSDebian10.011.09.0Fedora Project Fedora
OSFedoraproject333435Netapp Snapmanager
APPNetappall versionsOracle Banking Cash Management
APPOracle14.214.314.5Oracle Banking Corporate Lending Process Management
APPOracle14.2.014.3.014.5.0Oracle Banking Credit Facilities Process Management
APPOracle14.2.014.3.014.5.0Oracle Banking Supply Chain Finance
APPOracle14.2.0Oracle Banking Trade Finance Process Management
APPOracle14.5.0Oracle Business Activity Monitoring
APPOracle11.1.1.9.012.2.1.3.012.2.1.4.0Oracle Communications Brm Elastic Charging Engine
APPOracle11.312.0Oracle Communications Unified Inventory Management
APPOracle7.3.47.3.57.4.07.4.17.4.2Oracle Enterprise Manager Ops Center
APPOracle12.4.0.0Oracle Retail Customer Insights
APPOracle15.0.216.0.2Oracle Retail Xstore Point Of Service
APPOracle16.0.617.0.418.0.319.0.220.0.1Oracle Webcenter Portal
APPOracle12.2.1.3.012.2.1.4.0Oracle Webcenter Sites
APPOracle12.2.1.3.012.2.1.4.0Xstream
APPXstream< 1.4.17
Related vulnerabilities
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki