Buffer overflow in xstream - CVE-2024-47072
Published: November 7, 2024 / Updated: November 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing unstrusted input. A remote attacker can pass a specially crafted stream to the application, trigger a stack overflow and perform a denial of service (DoS) attack.
Successful exploitation of this vulnerability requires that XStream is configured to use the BinaryStreamDriver.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Server Module
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
Development Tools Module
openSUSE Leap
openEuler
B2B Advanced Communications
IBM Enterprise Content Management Text Search
IBM Tivoli Netcool Configuration Manager
IBM Business Automation Manager Open Editions
Datacap
Oracle Communications Policy Management
Oracle Retail Xstore Point of Service
Storage Copy Data Management
Hybrid Cloud Observability
IBM OmniFind Text Search Server for DB2 for i
IBM Process Mining
Confluence Data Center
Jira Service Management Server
Jira Service Management Data Center
Oracle Communications Unified Inventory Management
Bitbucket Data Center
Bamboo Server
Jira Software Data Center
Oracle Middleware Common Libraries and Tools
Oracle Banking APIs
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Data Analytics Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Discovery for IBM Cloud Pak for Data
Red Hat build of Keycloak
IBM Disconnected Log Collector
Confluence Server
Oracle Utilities Application Framework
Oracle Business Activity Monitoring
Bitbucket Server
Jira Software Server
JBoss Data Grid
IBM DB2
Oracle WebCenter Portal
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Unified Data Repository
Orion Platform
bea-stax-api
bea-stax
xstream-benchmark
xstream-hibernate
xstream-javadoc
xstream-parent
xstream
IBM FileNet Content Manager
How to mitigate CVE-2024-47072
B2B Advanced Communications - update to 1.0.0.12
IBM Disconnected Log Collector - update to 1.8.7
IBM Process Mining - update to 2.0
Confluence Data Center - addressed in versions 8.5.21, 9.2.2, 9.3.2
Confluence Server - addressed in versions 8.5.21, 9.2.2, 9.3.2
Jira Service Management Server - addressed in versions 5.12.19, 10.3.4, 10.5.0
Jira Service Management Data Center - addressed in versions 5.12.19, 10.3.4, 10.5.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.22
Bitbucket Data Center - addressed in versions 8.9.24, 8.19.14, 9.4.2
IBM Business Automation Manager Open Editions - update to 8.0.7
Bitbucket Server - addressed in versions 8.9.24, 8.19.14, 9.4.2
Bamboo Server - addressed in versions 9.2.21, 9.6.10, 10.2.1
Datacap - update to 9.1.10
Jira Software Data Center - addressed in versions 9.12.19, 10.3.4, 10.5.0
Jira Software Server - addressed in versions 9.12.19, 10.3.4, 10.5.0
IBM DB2 - addressed in versions 11.5.9, 12.1.2
Orion Platform - update to 2025.4.1
bea-stax-api - update to 1.2.0-150200.11.3.1
bea-stax - update to 1.2.0-150200.11.3.1
xstream-benchmark - update to 1.4.20-2
xstream-hibernate - update to 1.4.20-2
xstream-javadoc - update to 1.4.20-2
xstream-parent - update to 1.4.20-2
xstream - update to 1.4.20-2
xstream-javadoc - update to 1.4.21-150200.3.28.1
xstream-parent - update to 1.4.21-150200.3.28.1
xstream-benchmark - update to 1.4.21-150200.3.28.1
xstream - update to 1.4.21-150200.3.28.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF009, 5.5.12.0 IF004, 5.6.0.0 IF002
JBoss Data Grid - update to 8.5.2
Red Hat build of Keycloak - update to 26.2.5
Hybrid Cloud Observability - update to 2025.4.1
External References
Related Security Bulletins
- Remote denial of service in XStream
- openEuler update for xstream
- Multiple vulnerabilities in JBoss Data Grid 8.5
- SUSE update for bea-stax, xstream
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Buffer overflow in Oracle Business Activity Monitoring
- Bitbucket Data Center and Server update for xstream
- Multiple vulnerabilities in IBM Watson Discovery
- Bamboo Data Center and Server update for XStream
- IBM FileNet Content Manager (FNCM) Content Search Services (CSS) update for XStream
- Jira Service Management Data Center and Server update for xstream
- Jira Software Data Center and Server update for xstream
- Multiple vulnerabilities in IBM Tivoli Network Configuration Manager
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Oracle Communications Unified Inventory Management
- Multiple vulnerabilities in Oracle Banking APIs
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Network Analytics Data Director
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Data Analytics Function
- Buffer overflow in Oracle WebCenter Portal
- Multiple vulnerabilities in Oracle Utilities Application Framework
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Confluence Data Center and Server update for xstream
- Multiple vulnerabilities in Red Hat build of Keycloak 26.2
- Multiple vulnerabilities in Red Hat build of Keycloak 26.2
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in Oracle Middleware Common Libraries and Tools
- Multiple vulnerabilities in SolarWinds Observability
- Multiple vulnerabilities in SolarWinds Platform
- Multiple vulnerabilities in IBM OmniFind Text Search Server for DB2 for i
- IBM B2B Advanced Communications update for XStream
- Multiple vulnerabilities in IBM Datacap
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- IBM Db2 update for XStream