AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2021-21350.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.8CVSS 3.1 · nvd@nist.gov
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAnalyzedModified Oct 07, 2026

Disclosure summary

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

Source-reported weakness categories

CWE-434, CWE-502, NVD-CWE-noinfo

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2021-21350

Open original source · Updated Oct 07, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
netapponcommand_insight-
apacheactivemq* {"versionEndExcluding":"5.15.14"}
apacheactivemq5.16.0
apacheactivemq5.16.1
apachejmeter* {"versionEndExcluding":"5.5"}
xstreamxstream* {"versionEndExcluding":"1.4.16"}
debiandebian_linux9.0
debiandebian_linux10.0
debiandebian_linux11.0
fedoraprojectfedora33
fedoraprojectfedora34
fedoraprojectfedora35
oraclebanking_enterprise_default_management2.10.0
oraclebanking_enterprise_default_management2.12.0
oraclebanking_platform2.4.0
oraclebanking_platform2.7.1
oraclebanking_platform2.9.0
oraclebanking_platform2.12.0
oraclebanking_virtual_account_management14.2.0
oraclebanking_virtual_account_management14.3.0
oraclebanking_virtual_account_management14.5.0
oraclebusiness_activity_monitoring11.1.1.9.0
oraclebusiness_activity_monitoring12.2.1.3.0
oraclebusiness_activity_monitoring12.2.1.4.0
oraclecommunications_billing_and_revenue_management_elastic_charging_engine12.0.0.3.0
oraclecommunications_policy_management12.5.0
oraclecommunications_unified_inventory_management7.3.2
oraclecommunications_unified_inventory_management7.3.4
oraclecommunications_unified_inventory_management7.3.5
oraclecommunications_unified_inventory_management7.4.0
oraclecommunications_unified_inventory_management7.4.1
oracleretail_xstore_point_of_service16.0.6
oracleretail_xstore_point_of_service17.0.4
oracleretail_xstore_point_of_service18.0.3
oracleretail_xstore_point_of_service19.0.2
oraclewebcenter_portal11.1.1.9.0
oraclewebcenter_portal12.2.1.3.0
oraclewebcenter_portal12.2.1.4.0
oracleweblogic_server12.1.3.0.0
oracleweblogic_server12.2.1.3.0
oracleweblogic_server12.2.1.4.0
oracleweblogic_server14.1.1.0.0

Original records & references

PUBLISHED 2021-03-22T20:15:13-04:00
MODIFIED 2026-10-07T15:17:24-04:00
INGESTED 2026-10-08T12:30:35-04:00