Code Injection in xstream - CVE-2021-39144

 

Code Injection in xstream - CVE-2021-39144

Published: October 25, 2022 / Updated: December 17, 2024


Vulnerability identifier: #VU68720
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-39144
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in xStream. A remote attacker can pass specially crafted XML data to the application and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

xstream
Cloud Foundation
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Ubuntu
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Atlas eDiscovery Process Management
NSX Data Center for vSphere
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
JBoss Data Grid
Red Hat Single Sign-On
libxstream-java (Ubuntu package)
xstream (Red Hat package)
xstream
xstream-hibernate
xstream-benchmark
xstream-javadoc
xstream-parent
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager

How to mitigate CVE-2021-39144

Install updates from vendor's website.

xstream - update to 1.4.18
Atlas eDiscovery Process Management - update to 6.0.3.9.7
NSX Data Center for vSphere - update to 6.4.14
JBoss Data Grid - addressed in versions 7.3.10, 8.3.0
Red Hat Single Sign-On - update to 7.6.4
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
xstream (Red Hat package) - update to 1.3.1-16.el7_9
xstream - update to 1.4.18-1
xstream-hibernate - update to 1.4.18-1
xstream-benchmark - update to 1.4.18-1
xstream-javadoc - update to 1.4.18-1
xstream-parent - update to 1.4.18-1
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
xstream - update to 1.4.18-3.14.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
IBM Security Verify Governance - update to 10.0.1.0.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins