CVE-2017-15095Critical· 9.8▾ MidnightA deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of th…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
8.4%
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
jackson-databind >= 2.0.0, < 2.6.7.2jackson-databind >= 2.7.0, < 2.7.9.2jackson-databind >= 2.8.0, < 2.8.10jackson-databind = 2.9.0debian_linux = 8.0debian_linux = 9.0openshift_container_platform = 3.11satellite = 6.4satellite_capsule = 6.4openshift_container_platform = 4.1jboss_enterprise_application_platform = 6.0.0jboss_enterprise_application_platform = 6.4.0jboss_enterprise_application_platform = 7.1.0oncommand_balanceoncommand_performance_manageroncommand_shiftsnapcenterbanking_platform = 2.5.0banking_platform = 2.6.0banking_platform = 2.6.1banking_platform = 2.6.2clusterware = 12.1.0.2.0communications_billing_and_revenue_management = 7.5communications_billing_and_revenue_management = 12.0communications_diameter_signaling_router < 8.3communications_instant_messaging_server = 10.0.1.2.0database_server = 12.2.0.1database_server = 18.1enterprise_manager_for_virtualization = 13.2.2enterprise_manager_for_virtualization = 13.2.3enterprise_manager_for_virtualization = 13.3.1financial_services_analytical_applications_infrastructure = 8.0.2financial_services_analytical_applications_infrastructure = 8.0.3financial_services_analytical_applications_infrastructure = 8.0.4financial_services_analytical_applications_infrastructure = 8.0.5financial_services_analytical_applications_infrastructure = 8.0.6financial_services_analytical_applications_infrastructure = 8.0.7global_lifecycle_management_opatchauto < 12.2.0.1.14identity_manager = 11.1.2.3.0identity_manager = 12.2.1.3.0jd_edwards_enterpriseone_tools = 9.2primavera_unifier >= 17.1, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8utilities_advanced_spatial_and_operational_analytics = 2.7.0.1webcenter_portal = 12.2.1.3.0Upgrade past the affected range:
jackson-databind 2.8.10communications_diameter_signaling_router 8.3global_lifecycle_management_opatchauto 12.2.0.1.14Connected by shared product, vendor, weakness, or advisory.
CVE-2017-7525Critical· 9.8A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue meth…
CVE-2018-5968High· 8.1FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2018-11307Critical· 9.8An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5
CVE-2019-12086High· 7.5A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9
CVE-2019-12384Medium· 5.9FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization