{"id":"CVE-2019-16942","title":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10","summary":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the com…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"fasterxml","product":"jackson-databind","affected":["jackson-databind >= 2.0.0, < 2.6.7.3","jackson-databind >= 2.8.0, < 2.8.11.5","jackson-databind >= 2.9.0, < 2.9.10.1","debian_linux = 8.0","debian_linux = 9.0","debian_linux = 10.0","fedora = 30","fedora = 31","jboss_enterprise_application_platform = 7.2.0","jboss_enterprise_application_platform = 7.3","active_iq_unified_manager >= 7.3","active_iq_unified_manager >= 9.5","oncommand_api_services","oncommand_workflow_automation","service_level_manager","steelstore_cloud_integrated_storage","banking_platform = 2.4.0","banking_platform = 2.4.1","banking_platform = 2.5.0","banking_platform = 2.6.0","banking_platform = 2.6.1","banking_platform = 2.6.2","banking_platform = 2.7.0","banking_platform = 2.7.1","banking_platform = 2.9.0","communications_billing_and_revenue_management = 7.5.0.23.0","communications_billing_and_revenue_management = 12.0.0.3.0","communications_calendar_server = 8.0.0.2.0","communications_calendar_server = 8.0.0.3.0","communications_cloud_native_core_network_slice_selection_function = 1.2.1","communications_evolved_communications_application_server = 7.1","database_server = 12.2.0.1","database_server = 18c","database_server = 19c","global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0","global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0","global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2","goldengate_application_adapters = 19.1.0.0.0","jd_edwards_enterpriseone_orchestrator = 9.2","jd_edwards_enterpriseone_tools = 9.2","primavera_gateway >= 17.12.0, <= 17.12.6","primavera_gateway >= 18.8.0, <= 18.8.8","primavera_gateway = 19.12.0","primavera_unifier >= 17.7, <= 17.12","primavera_unifier = 16.1","primavera_unifier = 16.2","primavera_unifier = 18.8","primavera_unifier = 19.12","retail_merchandising_system = 15.0.3","retail_merchandising_system = 16.0.2","retail_merchandising_system = 16.0.3","retail_sales_audit = 14.1","siebel_engineering_-_installer_&_deployment <= 2.20.5","siebel_ui_framework <= 20.5","siebel_ui_framework = 20.6","webcenter_portal = 12.2.1.3.0","webcenter_portal = 12.2.1.4.0","webcenter_sites = 12.2.1.3.0","webcenter_sites = 12.2.1.4.0","weblogic_server = 12.2.1.3.0","weblogic_server = 12.2.1.4.0"],"patched":["jackson-databind 2.9.10.1"],"published":"2019-10-01","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:16.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-16942","references":[{"url":"https://access.redhat.com/errata/RHSA-2019:3901","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0159","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0160","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0161","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0164","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0445","label":"cve@mitre.org"},{"url":"https://github.com/FasterXML/jackson-databind/issues/2478","label":"cve@mitre.org"},{"url":"https://issues.apache.org/jira/browse/GEODE-7255","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5%40%3Cissues.geode.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954%40%3Cissues.geode.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370%40%3Cissues.geode.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","label":"cve@mitre.org"},{"url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","label":"cve@mitre.org"},{"url":"https://seclists.org/bugtraq/2019/Oct/6","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20191017-0006/","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2019/dsa-4542","label":"cve@mitre.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:3901","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0159","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0160","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0161","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0164","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0445","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/FasterXML/jackson-databind/issues/2478","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://issues.apache.org/jira/browse/GEODE-7255","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5%40%3Cissues.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954%40%3Cissues.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370%40%3Cissues.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://seclists.org/bugtraq/2019/Oct/6","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20191017-0006/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2019/dsa-4542","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.05728,"epssPercentile":0.92844,"ingestedAt":"2026-10-08T22:11:53.702Z","slug":"CVE-2019-16942","body":"## Overview\n\nA Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.\n\n## Affected\n\n- `jackson-databind >= 2.0.0, < 2.6.7.3`\n- `jackson-databind >= 2.8.0, < 2.8.11.5`\n- `jackson-databind >= 2.9.0, < 2.9.10.1`\n- `debian_linux = 8.0`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `fedora = 30`\n- `fedora = 31`\n- `jboss_enterprise_application_platform = 7.2.0`\n- `jboss_enterprise_application_platform = 7.3`\n- `active_iq_unified_manager >= 7.3`\n- `active_iq_unified_manager >= 9.5`\n- `oncommand_api_services`\n- `oncommand_workflow_automation`\n- `service_level_manager`\n- `steelstore_cloud_integrated_storage`\n- `banking_platform = 2.4.0`\n- `banking_platform = 2.4.1`\n- `banking_platform = 2.5.0`\n- `banking_platform = 2.6.0`\n- `banking_platform = 2.6.1`\n- `banking_platform = 2.6.2`\n- `banking_platform = 2.7.0`\n- `banking_platform = 2.7.1`\n- `banking_platform = 2.9.0`\n- `communications_billing_and_revenue_management = 7.5.0.23.0`\n- `communications_billing_and_revenue_management = 12.0.0.3.0`\n- `communications_calendar_server = 8.0.0.2.0`\n- `communications_calendar_server = 8.0.0.3.0`\n- `communications_cloud_native_core_network_slice_selection_function = 1.2.1`\n- `communications_evolved_communications_application_server = 7.1`\n- `database_server = 12.2.0.1`\n- `database_server = 18c`\n- `database_server = 19c`\n- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0`\n- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0`\n- `global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2`\n- `goldengate_application_adapters = 19.1.0.0.0`\n- `jd_edwards_enterpriseone_orchestrator = 9.2`\n- `jd_edwards_enterpriseone_tools = 9.2`\n- `primavera_gateway >= 17.12.0, <= 17.12.6`\n- `primavera_gateway >= 18.8.0, <= 18.8.8`\n- `primavera_gateway = 19.12.0`\n- `primavera_unifier >= 17.7, <= 17.12`\n- `primavera_unifier = 16.1`\n- `primavera_unifier = 16.2`\n- `primavera_unifier = 18.8`\n- `primavera_unifier = 19.12`\n- `retail_merchandising_system = 15.0.3`\n- `retail_merchandising_system = 16.0.2`\n- `retail_merchandising_system = 16.0.3`\n- `retail_sales_audit = 14.1`\n- `siebel_engineering_-_installer_&_deployment <= 2.20.5`\n- `siebel_ui_framework <= 20.5`\n- `siebel_ui_framework = 20.6`\n- `webcenter_portal = 12.2.1.3.0`\n- `webcenter_portal = 12.2.1.4.0`\n- `webcenter_sites = 12.2.1.3.0`\n- `webcenter_sites = 12.2.1.4.0`\n- `weblogic_server = 12.2.1.3.0`\n- `weblogic_server = 12.2.1.4.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jackson-databind 2.9.10.1`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":1.1,"exploitation":0,"ransomware":0},"changes":[]}