CVE-2019-14379Critical· 9.8▾ MidnightSubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
8.1%
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
jackson-databind >= 2.0.0, < 2.6.7.3jackson-databind >= 2.7.0, < 2.7.9.6jackson-databind >= 2.8.0, < 2.8.11.4jackson-databind >= 2.9.0, < 2.9.9.2debian_linux = 8.0active_iq_unified_manager >= 7.3active_iq_unified_manager >= 9.5oncommand_workflow_automationservice_level_managersnapcenterfedora = 29fedora = 30fedora = 31jboss_enterprise_application_platform = 7.2jboss_enterprise_application_platform = 7.3openshift_container_platform = 4.1single_sign-on = 7.3openshift_container_platform = 3.11banking_platform = 2.4.0banking_platform = 2.4.1banking_platform = 2.5.0banking_platform = 2.6.0banking_platform = 2.6.1banking_platform = 2.7.0banking_platform = 2.7.1communications_diameter_signaling_router = 8.0.0communications_diameter_signaling_router = 8.1communications_diameter_signaling_router = 8.2communications_diameter_signaling_router = 8.2.1communications_instant_messaging_server = 10.0.1.3.0financial_services_analytical_applications_infrastructure >= 8.0.2, <= 8.0.8goldengate_stream_analytics < 19.1.0.0.1jd_edwards_enterpriseone_orchestrator = 9.2jd_edwards_enterpriseone_tools = 9.2primavera_gateway = 15.2primavera_gateway = 16.2primavera_gateway = 17.12primavera_gateway = 18.8.0primavera_unifier >= 17.7, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8retail_customer_management_and_segmentation_foundation = 17.0retail_xstore_point_of_service = 7.1retail_xstore_point_of_service = 15.0retail_xstore_point_of_service = 16.0retail_xstore_point_of_service = 17.0retail_xstore_point_of_service = 18.0siebel_engineering_-_installer_&_deployment <= 19.8siebel_ui_framework <= 19.10xcode < 13.3Upgrade past the affected range:
jackson-databind 2.9.9.2goldengate_stream_analytics 19.1.0.0.1xcode 13.3Connected by shared product, vendor, weakness, or advisory.
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2017-15095Critical· 9.8A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of th…
CVE-2017-7525Critical· 9.8A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue meth…
CVE-2018-5968High· 8.1FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws
CVE-2020-11620High· 8.1FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
CVE-2019-14892Critical· 9.8A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes