Improper input validation in xstream - CVE-2021-39140

 

Improper input validation in xstream - CVE-2021-39140

Published: April 22, 2022 / Updated: May 5, 2026


Vulnerability identifier: #VU62511
CSH Severity: Medium
CVSS v4: 8.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H]
CVE-ID: CVE-2021-39140
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to improper input validation. A remote attacker can exploit this vulnerability to perform a denial of service attack.


Affected software

xstream
Oracle Communications Cloud Native Core Policy
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Ubuntu
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Atlas eDiscovery Process Management
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
libxstream-java (Ubuntu package)
xstream (Red Hat package)
xstream
xstream-hibernate
xstream-benchmark
xstream-javadoc
xstream-parent
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
JBoss Data Grid

How to mitigate CVE-2021-39140

Install updates from vendor's website.

xstream - update to 1.4.18
Atlas eDiscovery Process Management - update to 6.0.3.9.7
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
xstream (Red Hat package) - update to 1.3.1-16.el7_9
xstream - update to 1.4.18-1
xstream-hibernate - update to 1.4.18-1
xstream-benchmark - update to 1.4.18-1
xstream-javadoc - update to 1.4.18-1
xstream-parent - update to 1.4.18-1
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
xstream - update to 1.4.18-3.14.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
JBoss Data Grid - update to 8.3.0
IBM Security Verify Governance - update to 10.0.1.0.2

External References

Related Security Bulletins