Deserialization of Untrusted Data in xstream - CVE-2019-10173

 

Deserialization of Untrusted Data in xstream - CVE-2019-10173

Published: November 20, 2019


Vulnerability identifier: #VU22875
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10173
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data passed in XML or JSON formats within the xstream API. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

xstream
Oracle Utilities Framework
Oracle Banking Platform
Oracle Retail Xstore Point of Service
Oracle Endeca Information Discovery Studio
Oracle Business Activity Monitoring
Fuse
Oracle Communications Unified Inventory Management
EMC Data Protection Advisor
Integrated Diameter Intelligence Hub (IDIH)
Oracle WebCenter Portal
Oracle Communications BRM - Elastic Charging Engine
Red Hat Single Sign-On

How to mitigate CVE-2019-10173

Install updates from vendor's website.

xstream - update to 1.4.11
Fuse - addressed in versions 6.3.14, 7.5.0
Red Hat Single Sign-On - update to 7.3.6
EMC Data Protection Advisor - update to 19.11

External References

Related Security Bulletins