CVE-2019-10173: Oracle Banking Platform
Critical severity, CVSS 9.8. EPSS: 95% chance of exploitation in the next 30 days.
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Affected products
- Oracle Banking Platform: from 2.4.0, up to and including 2.10.0; version 2.4.0 only; version 2.7.1 only; version 2.9.0 only
- Oracle Business Activity Monitoring: version 11.1.1.9.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Communications Billing And Revenue Management Elastic Charging Engine: version 11.3.0.9.0 only; version 12.0.0.3.0 only
- Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
- Oracle Communications Unified Inventory Management: version 7.3.0 only; version 7.4.0 only
- Oracle Endeca Information Discovery Studio: version 3.2.0 only; version 3.2.0.0 only
- Oracle Retail Xstore Point Of Service: version 17.0 only
- Oracle Utilities Framework: from 4.3.0.1.0, up to and including 4.3.0.6.0; version 2.2.0.0.0 only; version 4.2.0.2.0 only; version 4.2.0.3.0 only; version 4.4.0.0.0 only
- Oracle Webcenter Portal: version 11.1.1.9.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
- XStream XStream: version 1.4.10 only
Published 2019-07-23. Last modified 2026-06-17.