← All CVEs

CVE-2019-10173

critical · 9.8

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

9.8
CVSS
95.0%
EPSS (exploit prob.)
100th
EPSS percentile
2019-07-23
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94CWE-502

Affected products

VendorProductAffected versions
xstreamxstream1.4.10
oraclebanking_platform>= 2.4.0, <= 2.10.0
oraclebanking_platform2.4.0
oraclebanking_platform2.7.1
oraclebanking_platform2.9.0
oraclebusiness_activity_monitoring11.1.1.9.0
oraclebusiness_activity_monitoring12.2.1.3.0
oraclebusiness_activity_monitoring12.2.1.4.0
oraclecommunications_billing_and_revenue_management_elastic_charging_engine11.3.0.9.0
oraclecommunications_billing_and_revenue_management_elastic_charging_engine12.0.0.3.0
oraclecommunications_diameter_signaling_router>= 8.0.0, <= 8.2.2
oraclecommunications_unified_inventory_management7.3.0
oraclecommunications_unified_inventory_management7.4.0
oracleendeca_information_discovery_studio3.2.0
oracleendeca_information_discovery_studio3.2.0.0
oracleretail_xstore_point_of_service17.0
oracleutilities_framework>= 4.3.0.1.0, <= 4.3.0.6.0
oracleutilities_framework2.2.0.0.0
oracleutilities_framework4.2.0.2.0
oracleutilities_framework4.2.0.3.0
oracleutilities_framework4.4.0.0.0
oraclewebcenter_portal11.1.1.9.0
oraclewebcenter_portal12.2.1.3.0
oraclewebcenter_portal12.2.1.4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-10173