Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2021-39144

CVE-2021-39144

Medium
Open
KEV
TLP:CLEAR

XStream Remote Code Execution Vulnerability

NVD CVE.org
Critical Infrastructure

AI Analysis

No AI analysis yet.

Description

XStream — XStream — XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

Details

EPSS Score
98.12%

99.9th percentile

Confidence
100%
CISA KEV
Date Added
Mar 10, 2023
Patch Due
Mar 31, 2023
Required Action
Apply updates per vendor instructions.
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.