{"id":"CVE-2019-17531","title":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10","summary":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apa…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"fasterxml","product":"jackson-databind","affected":["jackson-databind >= 2.0.0, < 2.6.7.3","jackson-databind >= 2.7.0, < 2.8.11.5","jackson-databind >= 2.9.0, < 2.9.10.1","debian_linux = 8.0","jboss_enterprise_application_platform = 7.2","jboss_enterprise_application_platform = 7.3","banking_platform = 2.4.0","banking_platform = 2.4.1","banking_platform = 2.5.0","banking_platform = 2.6.0","banking_platform = 2.6.1","banking_platform = 2.6.2","banking_platform = 2.7.0","banking_platform = 2.7.1","banking_platform = 2.9.0","communications_billing_and_revenue_management = 7.5.0.23.0","communications_billing_and_revenue_management = 12.0.0.3.0","communications_calendar_server = 8.0.0.2.0","communications_calendar_server = 8.0.0.3.0","communications_cloud_native_core_network_slice_selection_function = 1.2.1","communications_evolved_communications_application_server = 7.1","global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0","global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0","global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2","goldengate_application_adapters = 19.1.0.0.0","jd_edwards_enterpriseone_orchestrator = 9.2","jd_edwards_enterpriseone_tools = 9.2","primavera_gateway >= 17.7, <= 17.12.6","primavera_gateway >= 18.8.0, <= 18.8.8","primavera_gateway = 16.1","primavera_gateway = 16.2","primavera_gateway = 19.12.0","retail_merchandising_system = 15.0.3","retail_merchandising_system = 16.0.2","retail_merchandising_system = 16.0.3","retail_sales_audit = 14.1","siebel_engineering_-_installer_&_deployment <= 2.20.5","trace_file_analyzer = 12.2.0.1","trace_file_analyzer = 18c","trace_file_analyzer = 19c","webcenter_portal = 12.2.1.3.0","webcenter_portal = 12.2.1.4.0","webcenter_sites = 12.2.1.3.0","webcenter_sites = 12.2.1.4.0","weblogic_server = 12.2.1.3.0","weblogic_server = 12.2.1.4.0","oncommand_workflow_automation","steelstore_cloud_integrated_storage"],"patched":["jackson-databind 2.9.10.1"],"published":"2019-10-12","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:16.950","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-17531","references":[{"url":"https://access.redhat.com/errata/RHSA-2019:4192","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0159","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0160","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0161","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0164","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2020:0445","label":"cve@mitre.org"},{"url":"https://github.com/FasterXML/jackson-databind/issues/2498","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5%40%3Ccommits.pulsar.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","label":"cve@mitre.org"},{"url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20191024-0005/","label":"cve@mitre.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"cve@mitre.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"cve@mitre.org"},{"url":"https://access.redhat.com/errata/RHSA-2019:4192","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0159","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0160","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0161","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0164","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2020:0445","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/FasterXML/jackson-databind/issues/2498","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5%40%3Ccommits.pulsar.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20191024-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.05373,"epssPercentile":0.92445,"ingestedAt":"2026-10-08T22:11:53.702Z","slug":"CVE-2019-17531","body":"## Overview\n\nA Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.\n\n## Affected\n\n- `jackson-databind >= 2.0.0, < 2.6.7.3`\n- `jackson-databind >= 2.7.0, < 2.8.11.5`\n- `jackson-databind >= 2.9.0, < 2.9.10.1`\n- `debian_linux = 8.0`\n- `jboss_enterprise_application_platform = 7.2`\n- `jboss_enterprise_application_platform = 7.3`\n- `banking_platform = 2.4.0`\n- `banking_platform = 2.4.1`\n- `banking_platform = 2.5.0`\n- `banking_platform = 2.6.0`\n- `banking_platform = 2.6.1`\n- `banking_platform = 2.6.2`\n- `banking_platform = 2.7.0`\n- `banking_platform = 2.7.1`\n- `banking_platform = 2.9.0`\n- `communications_billing_and_revenue_management = 7.5.0.23.0`\n- `communications_billing_and_revenue_management = 12.0.0.3.0`\n- `communications_calendar_server = 8.0.0.2.0`\n- `communications_calendar_server = 8.0.0.3.0`\n- `communications_cloud_native_core_network_slice_selection_function = 1.2.1`\n- `communications_evolved_communications_application_server = 7.1`\n- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0`\n- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0`\n- `global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2`\n- `goldengate_application_adapters = 19.1.0.0.0`\n- `jd_edwards_enterpriseone_orchestrator = 9.2`\n- `jd_edwards_enterpriseone_tools = 9.2`\n- `primavera_gateway >= 17.7, <= 17.12.6`\n- `primavera_gateway >= 18.8.0, <= 18.8.8`\n- `primavera_gateway = 16.1`\n- `primavera_gateway = 16.2`\n- `primavera_gateway = 19.12.0`\n- `retail_merchandising_system = 15.0.3`\n- `retail_merchandising_system = 16.0.2`\n- `retail_merchandising_system = 16.0.3`\n- `retail_sales_audit = 14.1`\n- `siebel_engineering_-_installer_&_deployment <= 2.20.5`\n- `trace_file_analyzer = 12.2.0.1`\n- `trace_file_analyzer = 18c`\n- `trace_file_analyzer = 19c`\n- `webcenter_portal = 12.2.1.3.0`\n- `webcenter_portal = 12.2.1.4.0`\n- `webcenter_sites = 12.2.1.3.0`\n- `webcenter_sites = 12.2.1.4.0`\n- `weblogic_server = 12.2.1.3.0`\n- `weblogic_server = 12.2.1.4.0`\n- `oncommand_workflow_automation`\n- `steelstore_cloud_integrated_storage`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jackson-databind 2.9.10.1`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":1.1,"exploitation":0,"ransomware":0},"changes":[]}