Improper input validation in xstream - CVE-2021-39154
Published: January 18, 2022 / Updated: May 5, 2026
Vulnerability identifier: #VU59701
CSH Severity: High
CVSS v4: 9.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2021-39154
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation. A remote attacker can exploit this vulnerability to execute arbitrary code.
Affected software
xstream
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Ubuntu
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Atlas eDiscovery Process Management
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
Oracle Business Activity Monitoring
libxstream-java (Ubuntu package)
xstream (Red Hat package)
xstream
xstream-hibernate
xstream-benchmark
xstream-javadoc
xstream-parent
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
JBoss Data Grid
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Ubuntu
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Atlas eDiscovery Process Management
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
Oracle Business Activity Monitoring
libxstream-java (Ubuntu package)
xstream (Red Hat package)
xstream
xstream-hibernate
xstream-benchmark
xstream-javadoc
xstream-parent
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
JBoss Data Grid
How to mitigate CVE-2021-39154
Install updates from vendor's website.
xstream - update to 1.4.18
Atlas eDiscovery Process Management - update to 6.0.3.9.7
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
xstream (Red Hat package) - update to 1.3.1-16.el7_9
xstream - update to 1.4.18-1
xstream-hibernate - update to 1.4.18-1
xstream-benchmark - update to 1.4.18-1
xstream-javadoc - update to 1.4.18-1
xstream-parent - update to 1.4.18-1
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
xstream - update to 1.4.18-3.14.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
JBoss Data Grid - update to 8.3.0
IBM Security Verify Governance - update to 10.0.1.0.2
Atlas eDiscovery Process Management - update to 6.0.3.9.7
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
xstream (Red Hat package) - update to 1.3.1-16.el7_9
xstream - update to 1.4.18-1
xstream-hibernate - update to 1.4.18-1
xstream-benchmark - update to 1.4.18-1
xstream-javadoc - update to 1.4.18-1
xstream-parent - update to 1.4.18-1
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
xstream - update to 1.4.18-3.14.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
JBoss Data Grid - update to 8.3.0
IBM Security Verify Governance - update to 10.0.1.0.2
External References
Related Security Bulletins
- Improper input validation in Oracle Business Activity Monitoring
- Ubuntu update for libxstream-java
- Multiple vulnerabilities in IBM Atlas eDiscovery Process Management
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Tivoli Netcool Configuration Manager
- openEuler update for xstream
- Red Hat Enterprise Linux 7 update for xstream
- Multiple vulnerabilities in JBoss Data Grid 8.3
- SUSE update for xstream
- Fedora 33 update for xstream
- Fedora 34 update for xstream
- Fedora 35 update for xstream
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in xstream