CVE-2017-7525Critical· 9.8▾ AbyssalPoC availableA deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue meth…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 7.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
38%
5 GitHub repos (last check)
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
jackson-databind < 2.6.7.1jackson-databind >= 2.7.0, < 2.7.9.1jackson-databind >= 2.8.0, < 2.8.9jackson-databind = 2.9.0debian_linux = 8.0debian_linux = 9.0oncommand_balanceoncommand_performance_manageroncommand_shiftsnapcenteropenshift_container_platform = 4.1virtualization = 4.0virtualization_host = 4.0jboss_enterprise_application_platform = 6.0.0jboss_enterprise_application_platform = 6.4.0jboss_enterprise_application_platform = 7.0jboss_enterprise_application_platform = 7.1openshift_container_platform = 3.11banking_platform = 2.5.0banking_platform = 2.6.0banking_platform = 2.6.1banking_platform = 2.6.2communications_billing_and_revenue_management = 7.5communications_billing_and_revenue_management = 12.0communications_communications_policy_management >= 12.0, <= 12.5.2communications_diameter_signaling_route < 8.3communications_instant_messaging_server = 10.0.1communications_instant_messaging_server = 10.0.1.2.0enterprise_manager_for_virtualization = 13.2.2enterprise_manager_for_virtualization = 13.2.3enterprise_manager_for_virtualization = 13.3.1financial_services_analytical_applications_infrastructure = 8.0.2.0.0financial_services_analytical_applications_infrastructure = 8.0.3.0.0financial_services_analytical_applications_infrastructure = 8.0.4.0.0financial_services_analytical_applications_infrastructure = 8.0.5.0.0financial_services_analytical_applications_infrastructure = 8.0.6.0.0financial_services_analytical_applications_infrastructure = 8.0.7.0.0global_lifecycle_management_opatchauto < 12.2.0.1.14primavera_unifier >= 17.1, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8utilities_advanced_spatial_and_operational_analytics = 2.7.0.1webcenter_portal = 12.2.1.3.0Upgrade past the affected range:
jackson-databind 2.8.9communications_diameter_signaling_route 8.3global_lifecycle_management_opatchauto 12.2.0.1.14Connected by shared product, vendor, weakness, or advisory.
CVE-2017-15095Critical· 9.8A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of th…
CVE-2018-5968High· 8.1FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws
CVE-2019-12086High· 7.5A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9
CVE-2019-12384Medium· 5.9FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization
CVE-2020-11113High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…