VDB

RHSA-2014:0294

RHSA-2014:0294 PUBLISHED CVSS 6.800000190734863 MEDIUM

It was found that XStream could deserialize arbitrary user-supplied XML content, representing objects of any type. A remote attacker able to pass XML to XStream could use this flaw to perform a variety of attacks, including remote code execution in the context of the server running the XStream application.

Risk Scores

CVSS 2.0
6.800000190734863

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Data Virtualization 6.0

Timeline

  • Mar 13, 2014 CVE Published
  • Apr 29, 2026 Distribution Patch
  • May 14, 2026 CVE Updated
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Security Advisory
  • May 15, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›