---
id: CVE-2019-14892
title: >-
  A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5
  and 2.6.7.3, where it would permit polymorphic deserialization of a malicious
  object using commons-configuration 1 and 2 JNDI classes
summary: >-
  A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5
  and 2.6.7.3, where it would permit polymorphic deserialization of a malicious
  object using commons-configuration 1 and 2 JNDI classes. An attacker could use
  th…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-200
  - CWE-502
  - CWE-502
vendor: fasterxml
product: jackson-databind
affected:
  - 'jackson-databind >= 2.0.0, < 2.6.7.3'
  - 'jackson-databind >= 2.7.0, < 2.8.11.5'
  - 'jackson-databind >= 2.9.0, < 2.9.10'
  - decision_manager = 7.0
  - jboss_data_grid
  - jboss_data_grid = 7.0.0
  - jboss_enterprise_application_platform = 7.0
  - jboss_fuse = 7.0.0
  - openshift_container_platform = 4.3
  - process_automation = 7.0
  - geode = 1.12.0
patched:
  - jackson-databind 2.9.10
published: '2020-03-02'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:14.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-14892'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2020:0729'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892'
    label: secalert@redhat.com
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2462'
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: secalert@redhat.com
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20200904-0005/'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2020:0729'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2462'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200904-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.05622
epssPercentile: 0.92737
ingestedAt: '2026-10-08T22:11:53.711Z'
---

## Overview

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

## Affected

- `jackson-databind >= 2.0.0, < 2.6.7.3`
- `jackson-databind >= 2.7.0, < 2.8.11.5`
- `jackson-databind >= 2.9.0, < 2.9.10`
- `decision_manager = 7.0`
- `jboss_data_grid`
- `jboss_data_grid = 7.0.0`
- `jboss_enterprise_application_platform = 7.0`
- `jboss_fuse = 7.0.0`
- `openshift_container_platform = 4.3`
- `process_automation = 7.0`
- `geode = 1.12.0`

## Remediation

Upgrade past the affected range:

- `jackson-databind 2.9.10`
