Input validation error in xstream - CVE-2013-7285
Published: November 20, 2019 / Updated: April 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input passed in XML and JSON formats to the Xstream API. A remote attacker can send specially crafted request to the affected application and execute arbitrary code on the target system.
Affected software
Gentoo Linux
Fuse
RSA Authentication Manager
Storage Copy Data Management
IBM Watson Discovery for IBM Cloud Pak for Data
EMC Data Protection Advisor
Red Hat Single Sign-On
How to mitigate CVE-2013-7285
Fuse - addressed in versions 6.3.14, 7.5.0
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3 Hotfix 3, 8.7 SP2 Patch 6 Hotfix 1, 8.8 Patch 3 Hotifx 2, 8.9 Patch 1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
Red Hat Single Sign-On - update to 7.3.6
EMC Data Protection Advisor - update to 19.11
External References
- http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html
- http://seclists.org/oss-sec/2014/q1/69
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369@%3Cissues.activemq.apache.org%3E
- https://www.mail-archive.com/user@xstream.codehaus.org/msg00604.html
- https://www.mail-archive.com/user@xstream.codehaus.org/msg00607.html
- https://x-stream.github.io/CVE-2013-7285.html
Related Security Bulletins
- Remote code execution in xstream API
- Multiple vulnerabilities in Red Hat Fuse
- Gentoo update for XStream
- Multiple vulnerabilities in Red Hat JBoss Fuse/A-MQ
- Multiple vulnerabilities in Dell Protection Advisor
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3
- Multiple vulnerabilities in IBM Storage Copy Data Management
- RSA Authentication Manager update for third-party components
- RSA Authentication Manager update for third-party components