---
id: CVE-2021-21349
title: XStream is a Java library to serialize objects to XML and back again
summary: >-
  XStream is a Java library to serialize objects to XML and back again. In
  XStream before version 1.4.16, there is a vulnerability which may allow a
  remote attacker to request data from internal resources that are not publicly
  available on…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N'
cwe:
  - CWE-502
  - CWE-918
vendor: netapp
product: oncommand_insight
affected:
  - oncommand_insight
  - activemq < 5.15.14
  - activemq = 5.16.0
  - activemq = 5.16.1
  - jmeter < 5.5
  - xstream < 1.4.16
  - debian_linux = 9.0
  - debian_linux = 10.0
  - debian_linux = 11.0
  - fedora = 33
  - fedora = 34
  - fedora = 35
  - banking_enterprise_default_management = 2.10.0
  - banking_enterprise_default_management = 2.12.0
  - banking_platform = 2.4.0
  - banking_platform = 2.7.1
  - banking_platform = 2.9.0
  - banking_platform = 2.12.0
  - banking_virtual_account_management = 14.2.0
  - banking_virtual_account_management = 14.3.0
  - banking_virtual_account_management = 14.5.0
  - business_activity_monitoring = 11.1.1.9.0
  - business_activity_monitoring = 12.2.1.3.0
  - business_activity_monitoring = 12.2.1.4.0
  - >-
    communications_billing_and_revenue_management_elastic_charging_engine =
    12.0.0.3.0
  - communications_policy_management = 12.5.0
  - communications_unified_inventory_management = 7.3.2
  - communications_unified_inventory_management = 7.3.4
  - communications_unified_inventory_management = 7.3.5
  - communications_unified_inventory_management = 7.4.0
  - communications_unified_inventory_management = 7.4.1
  - graalvm = 20.3.4
  - graalvm = 21.3.0
  - java_se = 7u321
  - java_se = 8u311
  - retail_xstore_point_of_service = 16.0.6
  - retail_xstore_point_of_service = 17.0.4
  - retail_xstore_point_of_service = 18.0.3
  - retail_xstore_point_of_service = 19.0.2
  - webcenter_portal = 11.1.1.9.0
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
patched:
  - activemq 5.15.14
  - jmeter 5.5
  - xstream 1.4.16
published: '2021-03-23'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:24.667'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-21349'
references:
  - url: 'http://x-stream.github.io/changes.html#1.4.16'
    label: security-advisories@github.com
  - url: >-
      https://github.com/x-stream/xstream/security/advisories/GHSA-f6hm-88x3-mfjv
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r9ac71b047767205aa22e3a08cb33f3e0586de6b2fac48b425c6e16b0%40%3Cdev.jmeter.apache.org%3E
    label: security-advisories@github.com
  - url: 'https://lists.debian.org/debian-lts-announce/2021/04/msg00002.html'
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
    label: security-advisories@github.com
  - url: 'https://security.netapp.com/advisory/ntap-20210430-0002/'
    label: security-advisories@github.com
  - url: 'https://www.debian.org/security/2021/dsa-5004'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security-advisories@github.com
  - url: 'https://x-stream.github.io/CVE-2021-21349.html'
    label: security-advisories@github.com
  - url: 'https://x-stream.github.io/security.html#workaround'
    label: security-advisories@github.com
  - url: 'http://x-stream.github.io/changes.html#1.4.16'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/x-stream/xstream/security/advisories/GHSA-f6hm-88x3-mfjv
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd%40%3Cusers.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9ac71b047767205aa22e3a08cb33f3e0586de6b2fac48b425c6e16b0%40%3Cdev.jmeter.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/04/msg00002.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210430-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-5004'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://x-stream.github.io/CVE-2021-21349.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://x-stream.github.io/security.html#workaround'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T18:45:30.622158Z'
epss: 0.46826
epssPercentile: 0.98798
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/s-index/CVE-2021-21349'
  checkedAt: '2026-10-08T08:12:27.369Z'
exploitAvailable: true
ingestedAt: '2026-10-07T19:44:15.642Z'
---

## Overview

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

## Affected

- `oncommand_insight`
- `activemq < 5.15.14`
- `activemq = 5.16.0`
- `activemq = 5.16.1`
- `jmeter < 5.5`
- `xstream < 1.4.16`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `fedora = 33`
- `fedora = 34`
- `fedora = 35`
- `banking_enterprise_default_management = 2.10.0`
- `banking_enterprise_default_management = 2.12.0`
- `banking_platform = 2.4.0`
- `banking_platform = 2.7.1`
- `banking_platform = 2.9.0`
- `banking_platform = 2.12.0`
- `banking_virtual_account_management = 14.2.0`
- `banking_virtual_account_management = 14.3.0`
- `banking_virtual_account_management = 14.5.0`
- `business_activity_monitoring = 11.1.1.9.0`
- `business_activity_monitoring = 12.2.1.3.0`
- `business_activity_monitoring = 12.2.1.4.0`
- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0.0.3.0`
- `communications_policy_management = 12.5.0`
- `communications_unified_inventory_management = 7.3.2`
- `communications_unified_inventory_management = 7.3.4`
- `communications_unified_inventory_management = 7.3.5`
- `communications_unified_inventory_management = 7.4.0`
- `communications_unified_inventory_management = 7.4.1`
- `graalvm = 20.3.4`
- `graalvm = 21.3.0`
- `java_se = 7u321`
- `java_se = 8u311`
- `retail_xstore_point_of_service = 16.0.6`
- `retail_xstore_point_of_service = 17.0.4`
- `retail_xstore_point_of_service = 18.0.3`
- `retail_xstore_point_of_service = 19.0.2`
- `webcenter_portal = 11.1.1.9.0`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`

## Remediation

Upgrade past the affected range:

- `activemq 5.15.14`
- `jmeter 5.5`
- `xstream 1.4.16`
