CVE-2019-16942Critical· 9.8▾ MidnightA Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the com…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.7%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.
jackson-databind >= 2.0.0, < 2.6.7.3jackson-databind >= 2.8.0, < 2.8.11.5jackson-databind >= 2.9.0, < 2.9.10.1debian_linux = 8.0debian_linux = 9.0debian_linux = 10.0fedora = 30fedora = 31jboss_enterprise_application_platform = 7.2.0jboss_enterprise_application_platform = 7.3active_iq_unified_manager >= 7.3active_iq_unified_manager >= 9.5oncommand_api_servicesoncommand_workflow_automationservice_level_managersteelstore_cloud_integrated_storagebanking_platform = 2.4.0banking_platform = 2.4.1banking_platform = 2.5.0banking_platform = 2.6.0banking_platform = 2.6.1banking_platform = 2.6.2banking_platform = 2.7.0banking_platform = 2.7.1banking_platform = 2.9.0communications_billing_and_revenue_management = 7.5.0.23.0communications_billing_and_revenue_management = 12.0.0.3.0communications_calendar_server = 8.0.0.2.0communications_calendar_server = 8.0.0.3.0communications_cloud_native_core_network_slice_selection_function = 1.2.1communications_evolved_communications_application_server = 7.1database_server = 12.2.0.1database_server = 18cdatabase_server = 19cglobal_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2goldengate_application_adapters = 19.1.0.0.0jd_edwards_enterpriseone_orchestrator = 9.2jd_edwards_enterpriseone_tools = 9.2primavera_gateway >= 17.12.0, <= 17.12.6primavera_gateway >= 18.8.0, <= 18.8.8primavera_gateway = 19.12.0primavera_unifier >= 17.7, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8primavera_unifier = 19.12retail_merchandising_system = 15.0.3retail_merchandising_system = 16.0.2retail_merchandising_system = 16.0.3retail_sales_audit = 14.1siebel_engineering_-_installer_&_deployment <= 2.20.5siebel_ui_framework <= 20.5siebel_ui_framework = 20.6webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0webcenter_sites = 12.2.1.3.0webcenter_sites = 12.2.1.4.0weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0Upgrade past the affected range:
jackson-databind 2.9.10.1Connected by shared product, vendor, weakness, or advisory.
CVE-2019-14893Critical· 9.8A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…
CVE-2019-14892Critical· 9.8A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes
CVE-2019-20330Critical· 9.8FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2020-36182High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-35728High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/jav…
CVE-2020-14061High· 8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnect…