Loading
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Use CWE-78, Oracle vendor hub and Endeca Information Discovery Studio product page to widen CVE-2013-7285 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-17571, CVE-2019-10173 and CVE-2017-5645 for nearby disclosures in the same product family.