← All CVEs

CVE-2013-7285

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

9.8
CVSS
84.4%
EPSS (exploit prob.)
100th
EPSS percentile
2019-05-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
oracleendeca_information_discovery_studio3.2.0
apacheactivemq5.15.8
xstreamxstream<= 1.4.6
xstreamxstream1.4.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-7285