Disclosure summary
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Source-reported weakness categories
CWE-78
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2013-7285
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| oracle | endeca_information_discovery_studio | 3.2.0 |
| apache | activemq | 5.15.8 |
| xstream | xstream | * {"versionEndIncluding":"1.4.6"} |
| xstream | xstream | 1.4.10 |
Original records & references
- NIST NVD record
- CVE Program record
- lists.apache.org — Mailing List
- lists.apache.org — Mailing List
- www.mail-archive.com — Third Party Advisory
- www.mail-archive.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- x-stream.github.io — Exploit, Third Party Advisory
- lists.apache.org — Mailing List
- lists.apache.org — Mailing List
- www.mail-archive.com — Third Party Advisory
- www.mail-archive.com — Third Party Advisory
- www.oracle.com — Third Party Advisory
- x-stream.github.io — Exploit, Third Party Advisory
PUBLISHED 2019-05-15T13:29:00-04:00
MODIFIED 2026-10-08T17:17:03-04:00
INGESTED 2026-10-10T20:50:18-04:00