A security patch has been released for a flaw that was found in Xstream, a simple library to serialize objects to XML and back again. CVE-2021-39144 is a Remote Command Execution vulnerability with a CVSSv3 score of 9.8/10 which if exploited a malicious actor can get remote code execution in the context of 'root' on the appliance. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream.
Recommendation:[/subscribe_to_unlock_form]
A security patch has been released for a flaw that was found in Xstream, a simple library to serialize objects to XML and back again. CVE-2021-39144 is a Remote Command Execution vulnerability with a CVSSv3 score of 9.8/10 which if exploited a malicious actor can get remote code execution in the context of 'root' on the appliance. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream.
Recommendation:[emaillocker id="1283"]
We strongly recommend you to update to the latest version (6.4.14) to patch the vulnerability.
References:
The following reports contain further technical details:
https://www.vmware.com/security/advisories/VMSA-2022-0027.html
[/emaillocker]