CVE-2019-16943Critical· 9.8▾ MidnightA Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6s…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.9%
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.
jackson-databind >= 2.0.0, < 2.6.7.3jackson-databind >= 2.7.0, < 2.8.11.5jackson-databind >= 2.9.0, < 2.9.10.1debian_linux = 8.0debian_linux = 9.0debian_linux = 10.0fedora = 30fedora = 31jboss_enterprise_application_platform = 7.2jboss_enterprise_application_platform = 7.3banking_platform = 2.4.0banking_platform = 2.4.1banking_platform = 2.5.0banking_platform = 2.6.0banking_platform = 2.6.1banking_platform = 2.6.2banking_platform = 2.7.0banking_platform = 2.7.1banking_platform = 2.9.0communications_billing_and_revenue_management = 7.5.0.23.0communications_billing_and_revenue_management = 12.0.0.3.0communications_calendar_server = 8.0.0.2.0communications_calendar_server = 8.0.0.3.0communications_cloud_native_core_network_slice_selection_function = 1.2.1communications_evolved_communications_application_server = 7.1global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2goldengate_application_adapters = 19.1.0.0.0jd_edwards_enterpriseone_orchestrator = 9.2jd_edwards_enterpriseone_tools = 9.2primavera_gateway >= 17.7, <= 17.12.6primavera_gateway >= 18.8.0, <= 18.8.8primavera_gateway = 16.1primavera_gateway = 16.2primavera_gateway = 19.12.0retail_merchandising_system = 15.0.3retail_merchandising_system = 16.0.2retail_merchandising_system = 16.0.3retail_sales_audit = 14.1siebel_engineering_-_installer_&_deployment <= 2.20.5trace_file_analyzer = 12.2.0.1trace_file_analyzer = 18ctrace_file_analyzer = 19cwebcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0webcenter_sites = 12.2.1.3.0webcenter_sites = 12.2.1.4.0weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0active_iq_unified_manager >= 7.3active_iq_unified_manager >= 9.5oncommand_api_servicesoncommand_workflow_automationservice_level_managersteelstore_cloud_integrated_storageUpgrade past the affected range:
jackson-databind 2.9.10.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-35728High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/jav…
CVE-2020-14061High· 8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnect…
CVE-2020-11113High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-11112High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11111High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-10969High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.