CVE-2019-10173: Code Injection
A vulnerability was found in xstream API version 1.4.10, if the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON. This a regression of CVE-2013-7285 fixed in 1.4.7 (fixed) as of BPMS 6.0.1, the regression was introduced with xstream-1.4.10 implemented in RHPAM.
References: https://access.redhat.com/security/cve/cve-2013-7285
Other sources
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
It was found that xstream API version 1.4.10 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. This a regression of CVE-2013-7285 fixed in 1.4.7 (fixed) as of BPMS 6.0.1, the regression was introduced with xstream-1.4.10 implemented in RHPAM.
xstream API could allow a remote attacker to execute arbitrary commands on the system, caused by insecure XML deserialization. By sending a specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-10173?
CVE-2019-10173 is a vulnerability in the xstream API that allows a remote attacker to execute arbitrary commands on the system.
How severe is CVE-2019-10173?
CVE-2019-10173 is classified as critical with a severity value of 9.8.
Which software versions are affected by CVE-2019-10173?
Xstream API version 1.4.10 is affected by CVE-2019-10173.
How can I fix CVE-2019-10173?
To fix CVE-2019-10173, update to xstream API version 1.4.11 or later.
Where can I find more information about CVE-2019-10173?
You can find more information about CVE-2019-10173 in the references provided: https://access.redhat.com/security/cve/CVE-2013-7285, https://access.redhat.com/security/cve/cve-2013-7285, http://x-stream.github.io/changes.html#1.4.11.