CVE-2020-26217
PoC —CVSS 3.1
8.8 high
EPSS
85%p100
Published
()
Modified
Description
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
- Vendors
- xstreamdebiannetappapacheoracle
- Products
- xstream, debian linux, snapmanager, activemq, banking cash management, banking corporate lending process management, banking credit facilities process management, banking platform, banking supply chain finance, banking trade finance process management, banking virtual account management, business activity monitoring
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.