CVE-2013-7285
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
9.8
CVSS
84.4%
EPSS (exploit prob.)
100th
EPSS percentile
2019-05-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| oracle | endeca_information_discovery_studio | 3.2.0 |
| apache | activemq | 5.15.8 |
| xstream | xstream | <= 1.4.6 |
| xstream | xstream | 1.4.10 |
Check a specific version with /api/v1/cve/match.
References
- http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html
- http://seclists.org/oss-sec/2014/q1/69
- http://web.archive.org/web/20140204133306/http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html
- https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00604.html
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00607.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://x-stream.github.io/CVE-2013-7285.html
- http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html
- http://seclists.org/oss-sec/2014/q1/69
- http://web.archive.org/web/20140204133306/http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html
- https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00604.html
- https://www.mail-archive.com/user%40xstream.codehaus.org/msg00607.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://x-stream.github.io/CVE-2013-7285.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-7285