---
id: CVE-2019-17267
title: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind before
  2.9.10
summary: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind before
  2.9.10. It is related to
  net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: fasterxml
product: jackson-databind
affected:
  - 'jackson-databind >= 2.0.0, < 2.8.11.5'
  - 'jackson-databind >= 2.9.0, < 2.9.10'
  - active_iq_unified_manager >= 7.3
  - active_iq_unified_manager >= 9.5
  - oncommand_api_services
  - oncommand_workflow_automation
  - service_level_manager
  - steelstore_cloud_integrated_storage
  - debian_linux = 8.0
  - jboss_enterprise_application_platform = 7.2
  - jboss_enterprise_application_platform = 7.3
  - customer_management_and_segmentation_foundation < 18.0
  - goldengate_application_adapters = 19.1.0.0.0
  - retail_customer_management_and_segmentation_foundation = 17.0
  - weblogic_server = 12.2.1.3.0
patched:
  - jackson-databind 2.9.10
  - customer_management_and_segmentation_foundation 18.0
published: '2019-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:13.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-17267'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2019:3200'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: cve@mitre.org
  - url: >-
      https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10
    label: cve@mitre.org
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2460'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8%40%3Cdev.skywalking.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20191017-0006/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:3200'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2460'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8%40%3Cdev.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20191017-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T18:25:08.725826Z'
epss: 0.04628
epssPercentile: 0.91447
ingestedAt: '2026-10-07T19:44:15.636Z'
---

## Overview

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

## Affected

- `jackson-databind >= 2.0.0, < 2.8.11.5`
- `jackson-databind >= 2.9.0, < 2.9.10`
- `active_iq_unified_manager >= 7.3`
- `active_iq_unified_manager >= 9.5`
- `oncommand_api_services`
- `oncommand_workflow_automation`
- `service_level_manager`
- `steelstore_cloud_integrated_storage`
- `debian_linux = 8.0`
- `jboss_enterprise_application_platform = 7.2`
- `jboss_enterprise_application_platform = 7.3`
- `customer_management_and_segmentation_foundation < 18.0`
- `goldengate_application_adapters = 19.1.0.0.0`
- `retail_customer_management_and_segmentation_foundation = 17.0`
- `weblogic_server = 12.2.1.3.0`

## Remediation

Upgrade past the affected range:

- `jackson-databind 2.9.10`
- `customer_management_and_segmentation_foundation 18.0`
