---
id: CVE-2019-16943
title: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0
  through 2.9.10
summary: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0
  through 2.9.10. When Default Typing is enabled (either globally or for a
  specific property) for an externally exposed JSON endpoint and the service has
  the p6s…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: fasterxml
product: jackson-databind
affected:
  - 'jackson-databind >= 2.0.0, < 2.6.7.3'
  - 'jackson-databind >= 2.7.0, < 2.8.11.5'
  - 'jackson-databind >= 2.9.0, < 2.9.10.1'
  - debian_linux = 8.0
  - debian_linux = 9.0
  - debian_linux = 10.0
  - fedora = 30
  - fedora = 31
  - jboss_enterprise_application_platform = 7.2
  - jboss_enterprise_application_platform = 7.3
  - banking_platform = 2.4.0
  - banking_platform = 2.4.1
  - banking_platform = 2.5.0
  - banking_platform = 2.6.0
  - banking_platform = 2.6.1
  - banking_platform = 2.6.2
  - banking_platform = 2.7.0
  - banking_platform = 2.7.1
  - banking_platform = 2.9.0
  - communications_billing_and_revenue_management = 7.5.0.23.0
  - communications_billing_and_revenue_management = 12.0.0.3.0
  - communications_calendar_server = 8.0.0.2.0
  - communications_calendar_server = 8.0.0.3.0
  - communications_cloud_native_core_network_slice_selection_function = 1.2.1
  - communications_evolved_communications_application_server = 7.1
  - global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0
  - global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0
  - global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2
  - goldengate_application_adapters = 19.1.0.0.0
  - jd_edwards_enterpriseone_orchestrator = 9.2
  - jd_edwards_enterpriseone_tools = 9.2
  - 'primavera_gateway >= 17.7, <= 17.12.6'
  - 'primavera_gateway >= 18.8.0, <= 18.8.8'
  - primavera_gateway = 16.1
  - primavera_gateway = 16.2
  - primavera_gateway = 19.12.0
  - retail_merchandising_system = 15.0.3
  - retail_merchandising_system = 16.0.2
  - retail_merchandising_system = 16.0.3
  - retail_sales_audit = 14.1
  - siebel_engineering_-_installer_&_deployment <= 2.20.5
  - trace_file_analyzer = 12.2.0.1
  - trace_file_analyzer = 18c
  - trace_file_analyzer = 19c
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
  - webcenter_sites = 12.2.1.3.0
  - webcenter_sites = 12.2.1.4.0
  - weblogic_server = 12.2.1.3.0
  - weblogic_server = 12.2.1.4.0
  - active_iq_unified_manager >= 7.3
  - active_iq_unified_manager >= 9.5
  - oncommand_api_services
  - oncommand_workflow_automation
  - service_level_manager
  - steelstore_cloud_integrated_storage
patched:
  - jackson-databind 2.9.10.1
published: '2019-10-01'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:01.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-16943'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: cve@mitre.org
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2478'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd%40%3Ccommits.iceberg.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/
    label: cve@mitre.org
  - url: >-
      https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
    label: cve@mitre.org
  - url: 'https://seclists.org/bugtraq/2019/Oct/6'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20191017-0006/'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2019/dsa-4542'
    label: cve@mitre.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2478'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd%40%3Ccommits.iceberg.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/bugtraq/2019/Oct/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20191017-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2019/dsa-4542'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.04901
epssPercentile: 0.91862
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-07T20:04:24.547505Z'
ingestedAt: '2026-10-07T20:46:47.000Z'
---

## Overview

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

## Affected

- `jackson-databind >= 2.0.0, < 2.6.7.3`
- `jackson-databind >= 2.7.0, < 2.8.11.5`
- `jackson-databind >= 2.9.0, < 2.9.10.1`
- `debian_linux = 8.0`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `fedora = 30`
- `fedora = 31`
- `jboss_enterprise_application_platform = 7.2`
- `jboss_enterprise_application_platform = 7.3`
- `banking_platform = 2.4.0`
- `banking_platform = 2.4.1`
- `banking_platform = 2.5.0`
- `banking_platform = 2.6.0`
- `banking_platform = 2.6.1`
- `banking_platform = 2.6.2`
- `banking_platform = 2.7.0`
- `banking_platform = 2.7.1`
- `banking_platform = 2.9.0`
- `communications_billing_and_revenue_management = 7.5.0.23.0`
- `communications_billing_and_revenue_management = 12.0.0.3.0`
- `communications_calendar_server = 8.0.0.2.0`
- `communications_calendar_server = 8.0.0.3.0`
- `communications_cloud_native_core_network_slice_selection_function = 1.2.1`
- `communications_evolved_communications_application_server = 7.1`
- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0`
- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0`
- `global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2`
- `goldengate_application_adapters = 19.1.0.0.0`
- `jd_edwards_enterpriseone_orchestrator = 9.2`
- `jd_edwards_enterpriseone_tools = 9.2`
- `primavera_gateway >= 17.7, <= 17.12.6`
- `primavera_gateway >= 18.8.0, <= 18.8.8`
- `primavera_gateway = 16.1`
- `primavera_gateway = 16.2`
- `primavera_gateway = 19.12.0`
- `retail_merchandising_system = 15.0.3`
- `retail_merchandising_system = 16.0.2`
- `retail_merchandising_system = 16.0.3`
- `retail_sales_audit = 14.1`
- `siebel_engineering_-_installer_&_deployment <= 2.20.5`
- `trace_file_analyzer = 12.2.0.1`
- `trace_file_analyzer = 18c`
- `trace_file_analyzer = 19c`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`
- `webcenter_sites = 12.2.1.3.0`
- `webcenter_sites = 12.2.1.4.0`
- `weblogic_server = 12.2.1.3.0`
- `weblogic_server = 12.2.1.4.0`
- `active_iq_unified_manager >= 7.3`
- `active_iq_unified_manager >= 9.5`
- `oncommand_api_services`
- `oncommand_workflow_automation`
- `service_level_manager`
- `steelstore_cloud_integrated_storage`

## Remediation

Upgrade past the affected range:

- `jackson-databind 2.9.10.1`
