---
id: CVE-2019-14540
title: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind before
  2.9.10
summary: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind before
  2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: fasterxml
product: jackson-databind
affected:
  - 'jackson-databind >= 2.0.0, < 2.6.7.3'
  - 'jackson-databind >= 2.7.0, < 2.8.11.5'
  - 'jackson-databind >= 2.9.0, < 2.9.10'
  - oncommand_api_services
  - oncommand_workflow_automation
  - steelstore_cloud_integrated_storage
  - fedora = 30
  - fedora = 31
  - debian_linux = 8.0
  - debian_linux = 9.0
  - debian_linux = 10.0
  - jboss_enterprise_application_platform = 7.2
  - jboss_enterprise_application_platform = 7.3
  - banking_platform = 2.4.0
  - banking_platform = 2.4.1
  - banking_platform = 2.5.0
  - banking_platform = 2.6.0
  - banking_platform = 2.6.1
  - banking_platform = 2.7.0
  - banking_platform = 2.7.1
  - customer_management_and_segmentation_foundation = 18.0
  - 'financial_services_analytical_applications_infrastructure >= 8.0.2, <= 8.0.8'
  - global_lifecycle_management_opatch < 11.2.0.3.23
  - 'global_lifecycle_management_opatch >= 12.2.0.1.0, < 12.2.0.1.19'
  - 'global_lifecycle_management_opatch >= 13.9.4.0.0, < 13.9.4.2.1'
  - goldengate_application_adapters = 19.1.0.0.0
  - goldengate_stream_analytics < 19.1.0.0.1
  - 'mysql >= 5.7.0, <= 5.7.30'
  - 'mysql >= 8.0.0, <= 8.0.20'
  - primavera_gateway = 15.2
  - primavera_gateway = 15.2.18
  - primavera_gateway = 16.2
  - primavera_gateway = 16.2.11
  - primavera_gateway = 17.12
  - primavera_gateway = 17.12.6
  - primavera_gateway = 18.8.0
  - primavera_gateway = 18.8.8.1
  - 'primavera_unifier >= 17.7, <= 17.12'
  - primavera_unifier = 16.1
  - primavera_unifier = 16.2
  - primavera_unifier = 18.8
  - primavera_unifier = 19.12
  - retail_customer_management_and_segmentation_foundation = 17.0
  - retail_xstore_point_of_service = 7.1
  - retail_xstore_point_of_service = 15.0
  - retail_xstore_point_of_service = 16.0
  - retail_xstore_point_of_service = 17.0
  - retail_xstore_point_of_service = 18.0
  - weblogic_server = 12.2.1.3.0
patched:
  - jackson-databind 2.9.10
  - global_lifecycle_management_opatch 13.9.4.2.1
  - goldengate_stream_analytics 19.1.0.0.1
published: '2019-09-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:13.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-14540'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2019:3200'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: cve@mitre.org
  - url: >-
      https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x
    label: cve@mitre.org
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2410'
    label: cve@mitre.org
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2449'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6%40%3Cnotifications.zookeeper.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0%40%3Cissues.hbase.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb%40%3Ccommits.hbase.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/
    label: cve@mitre.org
  - url: 'https://seclists.org/bugtraq/2019/Oct/6'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20191004-0002/'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2019/dsa-4542'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: cve@mitre.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3200'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2410'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2449'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0%40%3Cissues.hbase.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb%40%3Ccommits.hbase.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/bugtraq/2019/Oct/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20191004-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2019/dsa-4542'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.10763
epssPercentile: 0.95729
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/LeadroyaL/cve-2019-14540-exploit'
  checkedAt: '2026-10-08T22:12:29.982Z'
exploitAvailable: true
ingestedAt: '2026-10-08T22:11:53.701Z'
---

## Overview

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

## Affected

- `jackson-databind >= 2.0.0, < 2.6.7.3`
- `jackson-databind >= 2.7.0, < 2.8.11.5`
- `jackson-databind >= 2.9.0, < 2.9.10`
- `oncommand_api_services`
- `oncommand_workflow_automation`
- `steelstore_cloud_integrated_storage`
- `fedora = 30`
- `fedora = 31`
- `debian_linux = 8.0`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `jboss_enterprise_application_platform = 7.2`
- `jboss_enterprise_application_platform = 7.3`
- `banking_platform = 2.4.0`
- `banking_platform = 2.4.1`
- `banking_platform = 2.5.0`
- `banking_platform = 2.6.0`
- `banking_platform = 2.6.1`
- `banking_platform = 2.7.0`
- `banking_platform = 2.7.1`
- `customer_management_and_segmentation_foundation = 18.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.2, <= 8.0.8`
- `global_lifecycle_management_opatch < 11.2.0.3.23`
- `global_lifecycle_management_opatch >= 12.2.0.1.0, < 12.2.0.1.19`
- `global_lifecycle_management_opatch >= 13.9.4.0.0, < 13.9.4.2.1`
- `goldengate_application_adapters = 19.1.0.0.0`
- `goldengate_stream_analytics < 19.1.0.0.1`
- `mysql >= 5.7.0, <= 5.7.30`
- `mysql >= 8.0.0, <= 8.0.20`
- `primavera_gateway = 15.2`
- `primavera_gateway = 15.2.18`
- `primavera_gateway = 16.2`
- `primavera_gateway = 16.2.11`
- `primavera_gateway = 17.12`
- `primavera_gateway = 17.12.6`
- `primavera_gateway = 18.8.0`
- `primavera_gateway = 18.8.8.1`
- `primavera_unifier >= 17.7, <= 17.12`
- `primavera_unifier = 16.1`
- `primavera_unifier = 16.2`
- `primavera_unifier = 18.8`
- `primavera_unifier = 19.12`
- `retail_customer_management_and_segmentation_foundation = 17.0`
- `retail_xstore_point_of_service = 7.1`
- `retail_xstore_point_of_service = 15.0`
- `retail_xstore_point_of_service = 16.0`
- `retail_xstore_point_of_service = 17.0`
- `retail_xstore_point_of_service = 18.0`
- `weblogic_server = 12.2.1.3.0`

## Remediation

Upgrade past the affected range:

- `jackson-databind 2.9.10`
- `global_lifecycle_management_opatch 13.9.4.2.1`
- `goldengate_stream_analytics 19.1.0.0.1`
