---
id: CVE-2021-21345
title: XStream is a Java library to serialize objects to XML and back again
summary: >-
  XStream is a Java library to serialize objects to XML and back again. In
  XStream before version 1.4.16, there is a vulnerability which may allow a
  remote attacker who has sufficient rights to execute commands of the host only
  by manipula…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N'
cwe:
  - CWE-94
  - CWE-502
  - CWE-78
vendor: netapp
product: oncommand_insight
affected:
  - oncommand_insight
  - activemq < 5.15.14
  - activemq = 5.16.0
  - activemq = 5.16.1
  - jmeter < 5.5
  - xstream < 1.4.16
  - debian_linux = 9.0
  - debian_linux = 10.0
  - debian_linux = 11.0
  - fedora = 33
  - fedora = 34
  - fedora = 35
  - banking_enterprise_default_management = 2.10.0
  - banking_enterprise_default_management = 2.12.0
  - banking_platform = 2.4.0
  - banking_platform = 2.7.1
  - banking_platform = 2.9.0
  - banking_platform = 2.12.0
  - banking_virtual_account_management = 14.2.0
  - banking_virtual_account_management = 14.3.0
  - banking_virtual_account_management = 14.5.0
  - business_activity_monitoring = 11.1.1.9.0
  - business_activity_monitoring = 12.2.1.3.0
  - business_activity_monitoring = 12.2.1.4.0
  - >-
    communications_billing_and_revenue_management_elastic_charging_engine =
    12.0.0.3.0
  - communications_policy_management = 12.5.0
  - communications_unified_inventory_management = 7.3.2
  - communications_unified_inventory_management = 7.3.4
  - communications_unified_inventory_management = 7.3.5
  - communications_unified_inventory_management = 7.4.0
  - communications_unified_inventory_management = 7.4.1
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - retail_xstore_point_of_service = 16.0.6
  - retail_xstore_point_of_service = 17.0.4
  - retail_xstore_point_of_service = 18.0.3
  - retail_xstore_point_of_service = 19.0.2
  - webcenter_portal = 11.1.1.9.0
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
patched:
  - activemq 5.15.14
  - jmeter 5.5
  - xstream 1.4.16
published: '2021-03-23'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:23.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-21345'
references:
  - url: 'http://x-stream.github.io/changes.html#1.4.16'
    label: security-advisories@github.com
  - url: >-
      https://github.com/x-stream/xstream/security/advisories/GHSA-hwpc-8xqv-jvj4
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r9ac71b047767205aa22e3a08cb33f3e0586de6b2fac48b425c6e16b0%40%3Cdev.jmeter.apache.org%3E
    label: security-advisories@github.com
  - url: 'https://lists.debian.org/debian-lts-announce/2021/04/msg00002.html'
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
    label: security-advisories@github.com
  - url: 'https://security.netapp.com/advisory/ntap-20210430-0002/'
    label: security-advisories@github.com
  - url: 'https://www.debian.org/security/2021/dsa-5004'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security-advisories@github.com
  - url: 'https://x-stream.github.io/CVE-2021-21345.html'
    label: security-advisories@github.com
  - url: 'https://x-stream.github.io/security.html#workaround'
    label: security-advisories@github.com
  - url: 'http://x-stream.github.io/changes.html#1.4.16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/x-stream/xstream/security/advisories/GHSA-hwpc-8xqv-jvj4
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9ac71b047767205aa22e3a08cb33f3e0586de6b2fac48b425c6e16b0%40%3Cdev.jmeter.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/04/msg00002.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210430-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-5004'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://x-stream.github.io/CVE-2021-21345.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://x-stream.github.io/security.html#workaround'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-07T18:46:47.946466Z'
epss: 0.72324
epssPercentile: 0.99425
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/shoucheng3/x-stream__xstream_CVE-2021-21345_1-4-15'
  nuclei:
    - CVE-2021-21345
  checkedAt: '2026-10-07T19:44:51.106Z'
exploitAvailable: true
ingestedAt: '2026-10-07T19:44:15.641Z'
---

## Overview

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

## Affected

- `oncommand_insight`
- `activemq < 5.15.14`
- `activemq = 5.16.0`
- `activemq = 5.16.1`
- `jmeter < 5.5`
- `xstream < 1.4.16`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `fedora = 33`
- `fedora = 34`
- `fedora = 35`
- `banking_enterprise_default_management = 2.10.0`
- `banking_enterprise_default_management = 2.12.0`
- `banking_platform = 2.4.0`
- `banking_platform = 2.7.1`
- `banking_platform = 2.9.0`
- `banking_platform = 2.12.0`
- `banking_virtual_account_management = 14.2.0`
- `banking_virtual_account_management = 14.3.0`
- `banking_virtual_account_management = 14.5.0`
- `business_activity_monitoring = 11.1.1.9.0`
- `business_activity_monitoring = 12.2.1.3.0`
- `business_activity_monitoring = 12.2.1.4.0`
- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0.0.3.0`
- `communications_policy_management = 12.5.0`
- `communications_unified_inventory_management = 7.3.2`
- `communications_unified_inventory_management = 7.3.4`
- `communications_unified_inventory_management = 7.3.5`
- `communications_unified_inventory_management = 7.4.0`
- `communications_unified_inventory_management = 7.4.1`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `retail_xstore_point_of_service = 16.0.6`
- `retail_xstore_point_of_service = 17.0.4`
- `retail_xstore_point_of_service = 18.0.3`
- `retail_xstore_point_of_service = 19.0.2`
- `webcenter_portal = 11.1.1.9.0`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`

## Remediation

Upgrade past the affected range:

- `activemq 5.15.14`
- `jmeter 5.5`
- `xstream 1.4.16`
