CVE-2018-14719Critical· 9.8▾ MidnightFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.7%
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
jackson-databind >= 2.0.0, < 2.6.7.3jackson-databind >= 2.7.0, < 2.7.9.5jackson-databind >= 2.8.0, < 2.8.11.3jackson-databind >= 2.9.0, < 2.9.7debian_linux = 8.0debian_linux = 9.0banking_platform = 2.5.0banking_platform = 2.6.0banking_platform = 2.6.1banking_platform = 2.6.2business_process_management_suite = 12.1.3.0.0business_process_management_suite = 12.2.1.3.0clusterware = 12.1.0.2.0communications_billing_and_revenue_management = 7.5communications_billing_and_revenue_management = 12.0database_server = 11.2.0.4database_server = 12.1.0.2database_server = 12.2.0.1database_server = 18cdatabase_server = 19centerprise_manager_for_virtualization = 13.2.2enterprise_manager_for_virtualization = 13.2.3enterprise_manager_for_virtualization = 13.3.1financial_services_analytical_applications_infrastructure = 8.0.2financial_services_analytical_applications_infrastructure = 8.0.3financial_services_analytical_applications_infrastructure = 8.0.4financial_services_analytical_applications_infrastructure = 8.0.5financial_services_analytical_applications_infrastructure = 8.0.6financial_services_analytical_applications_infrastructure = 8.0.7global_lifecycle_management_opatch < 11.2.0.3.23global_lifecycle_management_opatch >= 12.2.0.1.0, < 12.2.0.1.19global_lifecycle_management_opatch >= 13.9.4.0.0, < 13.9.4.2.1jdeveloper = 12.1.3.0.0jdeveloper = 12.2.1.3.0primavera_p6_enterprise_project_portfolio_management >= 17.7, <= 17.12primavera_p6_enterprise_project_portfolio_management = 15.1primavera_p6_enterprise_project_portfolio_management = 15.2primavera_p6_enterprise_project_portfolio_management = 16.1primavera_p6_enterprise_project_portfolio_management = 16.2primavera_p6_enterprise_project_portfolio_management = 18.8primavera_unifier >= 17.7, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8retail_merchandising_system = 15.0retail_merchandising_system = 16.0retail_workforce_management_software = 1.60.9.0.0webcenter_portal = 12.2.1.3.0openshift_container_platform >= 3.11, < 3.11.153openshift_container_platform >= 4.6, < 4.6.26openshift_container_platform >= 4.1, < 4.1.18oncommand_workflow_automationsnapcentersteelstore_cloud_integrated_storageUpgrade past the affected range:
jackson-databind 2.9.7global_lifecycle_management_opatch 13.9.4.2.1openshift_container_platform 4.1.18Connected by shared product, vendor, weakness, or advisory.
CVE-2019-20330Critical· 9.8FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2017-15095Critical· 9.8A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of th…
CVE-2017-7525Critical· 9.8A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue meth…
CVE-2018-5968High· 8.1FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws
CVE-2019-14892Critical· 9.8A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes