Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-7285
HistoryMay 15, 2019 - 5:29 p.m.

Design/Logic Flaw

2019-05-1517:29:00
PRIOn knowledge base
www.prio-n.com
6

9.5 High

AI Score

Confidence

High

0.483 Medium

EPSS

Percentile

97.5%

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CPENameOperatorVersion
xstreamle1.4.6
xstreameq1.4.10