Improper input validation in xstream - CVE-2021-39139
Published: January 19, 2022 / Updated: May 5, 2026
Vulnerability identifier: #VU59813
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39139
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation. A remote attacker can exploit this vulnerability to execute arbitrary code.
Affected software
xstream
Oracle Communications Cloud Native Core Binding Support Function
Atlas eDiscovery Process Management
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Ubuntu
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Oracle Utilities Framework
Oracle Retail Xstore Point of Service
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
Oracle Utilities Testing Accelerator
Oracle Communications BRM - Elastic Charging Engine
Oracle Commerce Guided Search
Oracle WebCenter Portal
libxstream-java (Ubuntu package)
xstream (Red Hat package)
xstream
xstream-hibernate
xstream-benchmark
xstream-javadoc
xstream-parent
JBoss Data Grid
Oracle Communications Cloud Native Core Binding Support Function
Atlas eDiscovery Process Management
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Ubuntu
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Oracle Utilities Framework
Oracle Retail Xstore Point of Service
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
Oracle Utilities Testing Accelerator
Oracle Communications BRM - Elastic Charging Engine
Oracle Commerce Guided Search
Oracle WebCenter Portal
libxstream-java (Ubuntu package)
xstream (Red Hat package)
xstream
xstream-hibernate
xstream-benchmark
xstream-javadoc
xstream-parent
JBoss Data Grid
How to mitigate CVE-2021-39139
Install updates from vendor's website.
xstream - update to 1.4.18
Atlas eDiscovery Process Management - update to 6.0.3.9.7
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
xstream (Red Hat package) - update to 1.3.1-16.el7_9
xstream - update to 1.4.18-1
xstream-hibernate - update to 1.4.18-1
xstream-benchmark - update to 1.4.18-1
xstream-javadoc - update to 1.4.18-1
xstream-parent - update to 1.4.18-1
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
xstream - update to 1.4.18-3.14.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
JBoss Data Grid - update to 8.3.0
IBM Security Verify Governance - update to 10.0.1.0.2
Atlas eDiscovery Process Management - update to 6.0.3.9.7
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
xstream (Red Hat package) - update to 1.3.1-16.el7_9
xstream - update to 1.4.18-1
xstream-hibernate - update to 1.4.18-1
xstream-benchmark - update to 1.4.18-1
xstream-javadoc - update to 1.4.18-1
xstream-parent - update to 1.4.18-1
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
xstream - update to 1.4.18-3.14.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
JBoss Data Grid - update to 8.3.0
IBM Security Verify Governance - update to 10.0.1.0.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Utilities Testing Accelerator
- Multiple vulnerabilities in Oracle Utilities Framework
- Multiple vulnerabilities in Oracle Communications BRM - Elastic Charging Engine
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Improper input validation in Oracle WebCenter Portal
- Ubuntu update for libxstream-java
- Multiple vulnerabilities in IBM Atlas eDiscovery Process Management
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Tivoli Netcool Configuration Manager
- openEuler update for xstream
- Red Hat Enterprise Linux 7 update for xstream
- Multiple vulnerabilities in JBoss Data Grid 8.3
- SUSE update for xstream
- Fedora 35 update for xstream
- Fedora 33 update for xstream
- Fedora 34 update for xstream
- Fedora 33 update for xstream
- Fedora 34 update for xstream
- Fedora 35 update for xstream
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in xstream