CVE-2021-21345
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execu...
Affects 16 products across 6 vendors.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Attacker injects arbitrary code that is executed by the application process.
Software deserializes untrusted data without validation, allowing crafted objects to execute arbitrary code.
Show all 9
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
XStream versions prior to 1.4.16 are vulnerable to remote code execution due to improper handling of deserialization, allowing attackers to execute arbitrary commands on the host system.
BSID: BS-2021-GLOBAL-248401-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2021-21345?
What is the CVSS score for CVE-2021-21345?
Is CVE-2021-21345 actively exploited?
How do I remediate CVE-2021-21345?
What systems are affected by CVE-2021-21345?
| CVE ID | CVE-2021-21345 |
|---|---|
| BSID | BS-2021-GLOBAL-248401-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Published | 2021-03-23 |
| Last Modified | 2025-05-23 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
Source: NIST NVD / MITRE CVE Database
An attacker with sufficient rights can manipulate the processed input stream to execute commands on the host system. This is achieved by exploiting the deserialization process in XStream, which can be tricked into loading malicious objects.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Apache | Activemq | — |
| Apache | Jmeter | — |
| Debian | Debian Linux | — |
| Fedoraproject | Fedora | — |
| Netapp | Oncommand Insight | — |
| Oracle | Webcenter Portal | — |
| Oracle | Banking Virtual Account Management | — |
| Oracle | Business Activity Monitoring | — |
| Oracle | Communications Billing And Revenue Management Elastic Charging Engine | — |
| Oracle | Banking Enterprise Default Management | — |
| Oracle | Communications Unified Inventory Management | — |
| Oracle | Peoplesoft Enterprise Peopletools | — |
| Oracle | Communications Policy Management | — |
| Oracle | Retail Xstore Point Of Service | — |
| Oracle | Banking Platform | — |
| Xstream | Xstream | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 49d20fb2950ec50b3ffed65c8890601913ea16b3a7f371f71ee3cee0c60f7390145b7e248a7b3da2eb578ad54dadf4462352ac76c334c9ae704155cf10a1a854 |
Critical Severity - Know Your Exposure
A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →