CVE-2021-21345

CRITICAL

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execu...

Affects 16 products across 6 vendors.

BCS8.43
CVSS 3.19.9
EPSS72.3%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

CWE-94: Code Injection

Attacker injects arbitrary code that is executed by the application process.

CWE-502: Deserialization of Untrusted Data

Software deserializes untrusted data without validation, allowing crafted objects to execute arbitrary code.

Related Attack Patterns (CAPEC)
CAPEC-35 Leverage Executable Code in Non-Executable Files
via CWE-94
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
Show all 9
via CWE-94
via CWE-78
via CWE-94

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

XStream versions prior to 1.4.16 are vulnerable to remote code execution due to improper handling of deserialization, allowing attackers to execute arbitrary commands on the host system.

BSID: BS-2021-GLOBAL-248401-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-21345?
XStream versions prior to 1.4.16 are vulnerable to remote code execution due to improper handling of deserialization, allowing attackers to execute arbitrary commands on the host system.
What is the CVSS score for CVE-2021-21345?
CVE-2021-21345 has CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. EPSS: 72.3%.
Is CVE-2021-21345 actively exploited?
No confirmed active exploitation of CVE-2021-21345 as of 2026-05-30.
How do I remediate CVE-2021-21345?
Priority: IMMEDIATE. Advisory: https://www.oracle.com/security-alerts/cpuApr2021.html PSIRT: [email protected]
What systems are affected by CVE-2021-21345?
CVE-2021-21345 affects: Apache, Apache, Debian, Fedoraproject, Netapp, Oracle, Oracle, Oracle.
Vulnerability Details
CVE IDCVE-2021-21345
BSIDBS-2021-GLOBAL-248401-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published2021-03-23
Last Modified2025-05-23
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker with sufficient rights can manipulate the processed input stream to execute commands on the host system. This is achieved by exploiting the deserialization process in XStream, which can be tricked into loading malicious objects.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Apache Activemq
Apache Jmeter
Debian Debian Linux
Fedoraproject Fedora
Netapp Oncommand Insight
Oracle Webcenter Portal
Oracle Banking Virtual Account Management
Oracle Business Activity Monitoring
Oracle Communications Billing And Revenue Management Elastic Charging Engine
Oracle Banking Enterprise Default Management
Oracle Communications Unified Inventory Management
Oracle Peoplesoft Enterprise Peopletools
Oracle Communications Policy Management
Oracle Retail Xstore Point Of Service
Oracle Banking Platform
Xstream Xstream
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1950 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash49d20fb2950ec50b3ffed65c8890601913ea16b3a7f371f71ee3cee0c60f7390145b7e248a7b3da2eb578ad54dadf4462352ac76c334c9ae704155cf10a1a854
Related CVEs affecting Apache
CVE-1999-0926 10.0 Apache allows remote attackers to conduct a denial of service via a large num... CVE-2010-0425 10.0 modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 ... CVE-1999-0067 10.0 phf CGI program allows remote command execution through shell metacharacters. CVE-1999-1293 10.0 mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a deni... CVE-2003-0789 10.0 mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properl...
View all Apache CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →