CVE-2019-10173
CRITICALxstream API <1.4.11 - Use After Free
Title source: llmDescription
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
References (11)
Scores
CVSS v3
9.8
EPSS
0.9296
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
CWE-94
Status
published
Affected Products (25)
xstream/xstream
oracle/banking_platform
< 2.10.0
oracle/banking_platform
oracle/banking_platform
oracle/banking_platform
oracle/business_activity_monitoring
oracle/business_activity_monitoring
oracle/business_activity_monitoring
oracle/communications_billing_and_revenue_management_elastic_charging_engine
oracle/communications_billing_and_revenue_management_elastic_charging_engine
oracle/communications_diameter_signaling_router
< 8.2.2
oracle/communications_unified_inventory_management
oracle/communications_unified_inventory_management
oracle/endeca_information_discovery_studio
oracle/endeca_information_discovery_studio
... and 10 more
Timeline
Published
Jul 23, 2019
Tracked Since
Feb 18, 2026