PT-2016-5649 · Xstream+1 · Xstream+1

Guykoth

·

Published

2016-05-05

·

Updated

2025-05-23

·

CVE-2016-3674

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XStream versions prior to 1.4.9
Description The issue concerns multiple XML external entity (XXE) vulnerabilities in various drivers of XStream. These vulnerabilities allow remote attackers to read arbitrary files via a crafted XML document. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 1.4.9, update to version 1.4.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the affected drivers (Dom4JDriver, DomDriver, JDomDriver, JDom2Driver, SjsxpDriver, StandardStaxDriver, and WstxDriver) until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2016-3674
DLA-504-1
DSA-3575-1
GHSA-RGH3-987H-WPMW
MGASA-2016-0164
OPENSUSE-SU-2024:10592-1
USN-6978-1

Affected Products

Ubuntu
Xstream