CVE-2021-43859

Description

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.88

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-43859 are fixed in Thoughtworks-Xstream 1.4.19Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.7Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.8Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.9Windows
Vulnerabilities CVE-2021-29425,CVE-2021-43859,CVE-2022-23437,CVE-2022-34169,CVE-2022-40146 are affected in Oracle Financial Services Revenue Management and Billing 3.0Windows
Vulnerabilities CVE-2021-29425,CVE-2021-43859,CVE-2022-23437,CVE-2022-34169,CVE-2022-40146 are affected in Oracle Financial Services Revenue Management and Billing 3.1Windows
Vulnerabilities CVE-2021-29425,CVE-2021-43859,CVE-2022-23437,CVE-2022-34169,CVE-2022-40146 are affected in Oracle Financial Services Revenue Management and Billing 3.2Windows
Vulnerabilities CVE-2021-29425,CVE-2021-43859,CVE-2022-23437,CVE-2022-34169,CVE-2022-40146 are affected in Oracle Financial Services Revenue Management and Billing 4.0Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.7.1Windows
Multiple vulnerabilities are affected in Oracle Financial Services Revenue Management and Billing 2.9.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.4Windows
Vulnerabilities CVE-2021-43859 are fixed in Thoughtworks-Xstream for Linux 1.4.19Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234