7.5
CVSSv2

CVE-2019-10173

Published: 23/07/2019 Updated: 05/10/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

It was found that xstream API version 1.4.10 prior to 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote malicious user to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xstream project xstream 1.4.10

oracle banking platform 2.4.0

oracle webcenter portal 12.2.1.3.0

oracle webcenter portal 11.1.1.9.0

oracle utilities framework 4.2.0.3.0

oracle utilities framework 4.2.0.2.0

oracle utilities framework 2.2.0.0.0

oracle endeca information discovery studio 3.2.0

oracle utilities framework 4.4.0.0.0

oracle communications unified inventory management 7.4.0

oracle retail xstore point of service 17.0

oracle utilities framework

oracle communications diameter signaling router

oracle communications unified inventory management 7.3.0

oracle banking platform

oracle communications billing and revenue management elastic charging engine 11.3.0.9.0

oracle communications billing and revenue management elastic charging engine 12.0.0.3.0

oracle business activity monitoring 12.2.1.3.0

oracle business activity monitoring 11.1.1.9.0

oracle endeca information discovery studio 3.2.0.0

oracle banking platform 2.7.1

oracle banking platform 2.9.0

oracle webcenter portal 12.2.1.4.0

oracle business activity monitoring 12.2.1.4.0

Vendor Advisories

Synopsis Important: Red Hat Decision Manager 740 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Important: Red Hat Single Sign-On 736 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 73 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: Red Hat Data Grid 733 security update Type/Severity Security Advisory: Important Topic An update for Red Hat Data Grid is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis Important: Red Hat Process Automation Manager 740 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scor ...
Synopsis Important: Red Hat Fuse 750 security update Type/Severity Security Advisory: Important Topic A minor version update (from 74 to 75) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...
Synopsis Important: Red Hat JBoss Fuse/A-MQ 63 R14 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Fuse 63 and Red Hat JBoss A-MQ 63Red Hat Product Security has rated this update as having a security impact of Important A Common ...

Github Repositories

一句话脚本启动OpenRASP Cloud & Agent

quick-start Start OpenRASP Cloud(Server Side) with one bash scirpt in 5 mins Start OpenRASP Agent as attack target with one bash scirpt in 3 mins U can quick build openrasp test and development enviroment 一句话脚本启动OpenRASP Cloud 包含docker\dockercompose\es\mongo\mongoexpress # 建议修改cloudyaml + init/appconf + init/mongojs内默认密码zhimakaimen

JAVA 安全靶场,IAST 测试用例,JAVA漏洞复现,代码审计,SAST测试用例,被动扫描

JavaVul 介绍 Java 安全漏洞靶场,用于测试IAST和扫描器的被动扫描功能,集合了多个安全漏洞,利用docker镜像为每个靶场独立环境运行。 文章:IAST实践总结 部署 mvn版本 # mvn --version Apache Maven 305 (Red Hat 305-17) Maven home: /usr/share/maven Java version: 180_192, vendor: Oracle Corporation Java home: /usr/java/jd