Buffer overflow in xstream - CVE-2024-47072

 

Buffer overflow in xstream - CVE-2024-47072

Published: November 7, 2024 / Updated: November 8, 2024


Vulnerability identifier: #VU100095
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47072
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing unstrusted input. A remote attacker can pass a specially crafted stream to the application, trigger a stack overflow and perform a denial of service (DoS) attack.

Successful exploitation of this vulnerability requires that XStream is configured to use the BinaryStreamDriver.


Affected software

xstream
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Server Module
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
Development Tools Module
openSUSE Leap
openEuler
B2B Advanced Communications
IBM Enterprise Content Management Text Search
IBM Tivoli Netcool Configuration Manager
IBM Business Automation Manager Open Editions
Datacap
Oracle Communications Policy Management
Oracle Retail Xstore Point of Service
Storage Copy Data Management
Hybrid Cloud Observability
IBM OmniFind Text Search Server for DB2 for i
IBM Process Mining
Confluence Data Center
Jira Service Management Server
Jira Service Management Data Center
Oracle Communications Unified Inventory Management
Bitbucket Data Center
Bamboo Server
Jira Software Data Center
Oracle Middleware Common Libraries and Tools
Oracle Banking APIs
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Data Analytics Function
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Discovery for IBM Cloud Pak for Data
Red Hat build of Keycloak
IBM Disconnected Log Collector
Confluence Server
Oracle Utilities Application Framework
Oracle Business Activity Monitoring
Bitbucket Server
Jira Software Server
JBoss Data Grid
IBM DB2
Oracle WebCenter Portal
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Unified Data Repository
Orion Platform
bea-stax-api
bea-stax
xstream-benchmark
xstream-hibernate
xstream-javadoc
xstream-parent
xstream
IBM FileNet Content Manager

How to mitigate CVE-2024-47072

Install updates from vendor's website.

xstream - update to 1.4.21
B2B Advanced Communications - update to 1.0.0.12
IBM Disconnected Log Collector - update to 1.8.7
IBM Process Mining - update to 2.0
Confluence Data Center - addressed in versions 8.5.21, 9.2.2, 9.3.2
Confluence Server - addressed in versions 8.5.21, 9.2.2, 9.3.2
Jira Service Management Server - addressed in versions 5.12.19, 10.3.4, 10.5.0
Jira Service Management Data Center - addressed in versions 5.12.19, 10.3.4, 10.5.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.22
Bitbucket Data Center - addressed in versions 8.9.24, 8.19.14, 9.4.2
IBM Business Automation Manager Open Editions - update to 8.0.7
Bitbucket Server - addressed in versions 8.9.24, 8.19.14, 9.4.2
Bamboo Server - addressed in versions 9.2.21, 9.6.10, 10.2.1
Datacap - update to 9.1.10
Jira Software Data Center - addressed in versions 9.12.19, 10.3.4, 10.5.0
Jira Software Server - addressed in versions 9.12.19, 10.3.4, 10.5.0
IBM DB2 - addressed in versions 11.5.9, 12.1.2
Orion Platform - update to 2025.4.1
bea-stax-api - update to 1.2.0-150200.11.3.1
bea-stax - update to 1.2.0-150200.11.3.1
xstream-benchmark - update to 1.4.20-2
xstream-hibernate - update to 1.4.20-2
xstream-javadoc - update to 1.4.20-2
xstream-parent - update to 1.4.20-2
xstream - update to 1.4.20-2
xstream-javadoc - update to 1.4.21-150200.3.28.1
xstream-parent - update to 1.4.21-150200.3.28.1
xstream-benchmark - update to 1.4.21-150200.3.28.1
xstream - update to 1.4.21-150200.3.28.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF009, 5.5.12.0 IF004, 5.6.0.0 IF002
JBoss Data Grid - update to 8.5.2
Red Hat build of Keycloak - update to 26.2.5
Hybrid Cloud Observability - update to 2025.4.1

External References

Related Security Bulletins