Input validation error in xstream - CVE-2013-7285

 

Input validation error in xstream - CVE-2013-7285

Published: November 20, 2019 / Updated: April 7, 2020


Vulnerability identifier: #VU22876
CSH Severity: High
CVSS v4 BT: 8.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber]
CVE-ID: CVE-2013-7285
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input passed in XML and JSON formats to the Xstream API. A remote attacker can send specially crafted request to the affected application and execute arbitrary code on the target system.


Affected software

xstream
Gentoo Linux
Fuse
RSA Authentication Manager
Storage Copy Data Management
IBM Watson Discovery for IBM Cloud Pak for Data
EMC Data Protection Advisor
Red Hat Single Sign-On

How to mitigate CVE-2013-7285

Install updates from vendor's website.

xstream - update to 1.4.11
Fuse - addressed in versions 6.3.14, 7.5.0
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3 Hotfix 3, 8.7 SP2 Patch 6 Hotfix 1, 8.8 Patch 3 Hotifx 2, 8.9 Patch 1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
Red Hat Single Sign-On - update to 7.3.6
EMC Data Protection Advisor - update to 19.11

External References

Related Security Bulletins