Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29784
HistoryMar 23, 2021 - 2:07 a.m.

Remote Code Execution

2021-03-2302:07:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
vulnerability
remote code execution
xstream software
uncontrolled process references
deserialization
input stream manipulation
arbitrary code execution
remote server loaded code

EPSS

0.605

Percentile

97.8%

xstream is vulnerable to remote code execution. The vulnerability exists due to an uncontrolled process references on enum types at deserialization, allowing an attacker to manipulate the processed input stream and replace or inject objects, that result in execution of arbitrary code loaded from a remote server.

References