{"id":"CVE-2018-11307","title":"An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5","summary":"An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"fasterxml","product":"jackson-databind","affected":["jackson-databind >= 2.0.0, < 2.6.7.3","jackson-databind >= 2.7.0, < 2.7.9.4","jackson-databind >= 2.8.0, < 2.8.11.2","jackson-databind >= 2.9.0, < 2.9.6","openshift_container_platform = 3.11","openshift_container_platform = 4.1","clusterware = 12.1.0.2.0","communications_instant_messaging_server = 10.0.1.2.0","global_lifecycle_management_opatch < 11.2.0.3.23","global_lifecycle_management_opatch >= 12.2.0.1.0, < 12.2.0.1.19","global_lifecycle_management_opatch >= 13.9.4.0.0, < 13.9.4.2.1","retail_customer_management_and_segmentation_foundation = 17.0","utilities_advanced_spatial_and_operational_analytics = 2.7.0.1"],"patched":["jackson-databind 2.9.6","global_lifecycle_management_opatch 13.9.4.2.1"],"published":"2019-07-09","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:07.413","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-11307","references":[{"url":"https://access.redhat.com/errata/RHSA-2019:0782","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:1822","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:1823","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:2804","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:2858","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3002","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3140","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3149","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3892","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:4037","label":"cve@mitre.org"},{"url":"https://github.com/FasterXML/jackson-databind/issues/2032","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d%40%3Cissues.lucene.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","label":"cve@mitre.org"},{"url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","label":"cve@mitre.org"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7525","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:0782","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:1822","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:1823","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:2804","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:2858","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3002","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3140","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3149","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:3892","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2019:4037","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/FasterXML/jackson-databind/issues/2032","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d%40%3Cissues.lucene.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7525","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.0573,"epssPercentile":0.92847,"ingestedAt":"2026-10-08T22:11:53.698Z","slug":"CVE-2018-11307","body":"## Overview\n\nAn issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.\n\n## Affected\n\n- `jackson-databind >= 2.0.0, < 2.6.7.3`\n- `jackson-databind >= 2.7.0, < 2.7.9.4`\n- `jackson-databind >= 2.8.0, < 2.8.11.2`\n- `jackson-databind >= 2.9.0, < 2.9.6`\n- `openshift_container_platform = 3.11`\n- `openshift_container_platform = 4.1`\n- `clusterware = 12.1.0.2.0`\n- `communications_instant_messaging_server = 10.0.1.2.0`\n- `global_lifecycle_management_opatch < 11.2.0.3.23`\n- `global_lifecycle_management_opatch >= 12.2.0.1.0, < 12.2.0.1.19`\n- `global_lifecycle_management_opatch >= 13.9.4.0.0, < 13.9.4.2.1`\n- `retail_customer_management_and_segmentation_foundation = 17.0`\n- `utilities_advanced_spatial_and_operational_analytics = 2.7.0.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jackson-databind 2.9.6`\n- `global_lifecycle_management_opatch 13.9.4.2.1`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":1.1,"exploitation":0,"ransomware":0},"changes":[]}