Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-7285

88
FAUCET Score

CVE-2013-7285 is a critical remote code execution vulnerability affecting Xstream API versions up to 1.4.6 and 1.4.10, as well as products like Apache ActiveMQ and Oracle Endeca Information Discovery Studio. It allows unauthenticated attackers to execute arbitrary shell commands by manipulating input streams during XML or JSON unmarshaling. With a CVSS score of 9.8 (Critical) and a FAUCET Risk Score of 97/100, this vulnerability poses a severe risk due to its network-based attack vector and complete compromise potential. While not listed in CISA KEV, public exploit code exists on ExploitDB, and Nuclei templates are available, indicating active community awareness and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
3.2.0CPE matchmatch criteria
cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:*
5.15.8CPE matchmatch criteria
cpe:2.3:a:apache:activemq:5.15.8:*:*:*:*:*:*:*
<= 1.4.6CPE matchmatch criteria
cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:*
1.4.10CPE matchmatch criteria
cpe:2.3:a:xstream:xstream:1.4.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
84.36%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Nuclei: CVE-2013-7285 · Mar 12, 2023
ExploitDB: EDB-39193 · Jan 7, 2016
This CVE's current EPSS score of 0.8436 is in the 99th percentile among its peer group of 36,821 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (20)

mavenpatch availablevia ghsa
Product: com.thoughtworks.xstream:xstreamFixed in: 1.4.11
mavenpatch availablevia ghsa
Product: com.thoughtworks.xstream:xstreamFixed in: 1.4.7
redhatpatch availablevia redhat_api
Product: Fuse Management Console 7.1.0
View patch
redhatpatch availablevia redhat_api
Product: Fuse MQ Enterprise 7.1.0
View patch
redhatpatch availablevia redhat_api
Product: JBoss Enterprise BRMS Platform 5.3Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss A-MQ 6.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BPMS 6.0Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss BRMS 6.0Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Data Grid 6.2Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Fuse 6.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Fuse Service Works 6.0Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Portal 5.2Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Portal 6.2Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss SOA Platform 5.3Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: RHEV Manager version 3.3Fixed in: jasperreports-server-pro-0:5.5.0-6.el6ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Data Virtualization 6.0Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Fuse ESB Enterprise 7.1.0
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: xstream
redhatend of lifevia redhat_api
Product: OpenShift Enterprise 1Fixed in: xstream
redhatend of lifevia redhat_api
Product: Red Hat JBoss SOA Platform 4Fixed in: xstream

Vendor Advisories (2)

mavenGHSA-f554-x222-wgf7critical

Command Injection in Xstream

May 29, 2019
redhatCVE-2013-7285Important

XStream: remote code execution due to insecure XML deserialization

Dec 22, 2013

References

blog.diniscruz.com / 2013/12/xstream-remote-code-execution-exploit.html
Broken LinkNot ApplicableURL Repurposed
seclists.org / oss-sec/2014/q1/69
Mailing ListThird Party Advisory
lists.apache.org / thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3E
Mailing List
lists.apache.org / thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3E
Mailing List
mail-archive.com / user%40xstream.codehaus.org/msg00604.html
Third Party Advisory
mail-archive.com / user%40xstream.codehaus.org/msg00607.html
Third Party Advisory
oracle.com / security-alerts/cpuoct2020.html
Third Party Advisory
x-stream.github.io / CVE-2013-7285.html
ExploitThird Party Advisory
web.archive.org / web/20140204133306/http://blog.diniscruz.com/2013/12/xstream-remote-code-execution-exploit.html
Third Party Advisory