---
id: CVE-2019-17531
title: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0
  through 2.9.10
summary: >-
  A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0
  through 2.9.10. When Default Typing is enabled (either globally or for a
  specific property) for an externally exposed JSON endpoint and the service has
  the apa…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: fasterxml
product: jackson-databind
affected:
  - 'jackson-databind >= 2.0.0, < 2.6.7.3'
  - 'jackson-databind >= 2.7.0, < 2.8.11.5'
  - 'jackson-databind >= 2.9.0, < 2.9.10.1'
  - debian_linux = 8.0
  - jboss_enterprise_application_platform = 7.2
  - jboss_enterprise_application_platform = 7.3
  - banking_platform = 2.4.0
  - banking_platform = 2.4.1
  - banking_platform = 2.5.0
  - banking_platform = 2.6.0
  - banking_platform = 2.6.1
  - banking_platform = 2.6.2
  - banking_platform = 2.7.0
  - banking_platform = 2.7.1
  - banking_platform = 2.9.0
  - communications_billing_and_revenue_management = 7.5.0.23.0
  - communications_billing_and_revenue_management = 12.0.0.3.0
  - communications_calendar_server = 8.0.0.2.0
  - communications_calendar_server = 8.0.0.3.0
  - communications_cloud_native_core_network_slice_selection_function = 1.2.1
  - communications_evolved_communications_application_server = 7.1
  - global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0
  - global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0
  - global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2
  - goldengate_application_adapters = 19.1.0.0.0
  - jd_edwards_enterpriseone_orchestrator = 9.2
  - jd_edwards_enterpriseone_tools = 9.2
  - 'primavera_gateway >= 17.7, <= 17.12.6'
  - 'primavera_gateway >= 18.8.0, <= 18.8.8'
  - primavera_gateway = 16.1
  - primavera_gateway = 16.2
  - primavera_gateway = 19.12.0
  - retail_merchandising_system = 15.0.3
  - retail_merchandising_system = 16.0.2
  - retail_merchandising_system = 16.0.3
  - retail_sales_audit = 14.1
  - siebel_engineering_-_installer_&_deployment <= 2.20.5
  - trace_file_analyzer = 12.2.0.1
  - trace_file_analyzer = 18c
  - trace_file_analyzer = 19c
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
  - webcenter_sites = 12.2.1.3.0
  - webcenter_sites = 12.2.1.4.0
  - weblogic_server = 12.2.1.3.0
  - weblogic_server = 12.2.1.4.0
  - oncommand_workflow_automation
  - steelstore_cloud_integrated_storage
patched:
  - jackson-databind 2.9.10.1
published: '2019-10-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:16.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-17531'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2019:4192'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: cve@mitre.org
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2498'
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5%40%3Ccommits.pulsar.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E
    label: cve@mitre.org
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html'
    label: cve@mitre.org
  - url: >-
      https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20191024-0005/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2019:4192'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0159'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0160'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0161'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0164'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0445'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/FasterXML/jackson-databind/issues/2498'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5%40%3Ccommits.pulsar.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20191024-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.05373
epssPercentile: 0.92445
ingestedAt: '2026-10-08T22:11:53.702Z'
---

## Overview

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

## Affected

- `jackson-databind >= 2.0.0, < 2.6.7.3`
- `jackson-databind >= 2.7.0, < 2.8.11.5`
- `jackson-databind >= 2.9.0, < 2.9.10.1`
- `debian_linux = 8.0`
- `jboss_enterprise_application_platform = 7.2`
- `jboss_enterprise_application_platform = 7.3`
- `banking_platform = 2.4.0`
- `banking_platform = 2.4.1`
- `banking_platform = 2.5.0`
- `banking_platform = 2.6.0`
- `banking_platform = 2.6.1`
- `banking_platform = 2.6.2`
- `banking_platform = 2.7.0`
- `banking_platform = 2.7.1`
- `banking_platform = 2.9.0`
- `communications_billing_and_revenue_management = 7.5.0.23.0`
- `communications_billing_and_revenue_management = 12.0.0.3.0`
- `communications_calendar_server = 8.0.0.2.0`
- `communications_calendar_server = 8.0.0.3.0`
- `communications_cloud_native_core_network_slice_selection_function = 1.2.1`
- `communications_evolved_communications_application_server = 7.1`
- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.3.0`
- `global_lifecycle_management_nextgen_oui_framework = 12.2.1.4.0`
- `global_lifecycle_management_nextgen_oui_framework = 13.9.4.2.2`
- `goldengate_application_adapters = 19.1.0.0.0`
- `jd_edwards_enterpriseone_orchestrator = 9.2`
- `jd_edwards_enterpriseone_tools = 9.2`
- `primavera_gateway >= 17.7, <= 17.12.6`
- `primavera_gateway >= 18.8.0, <= 18.8.8`
- `primavera_gateway = 16.1`
- `primavera_gateway = 16.2`
- `primavera_gateway = 19.12.0`
- `retail_merchandising_system = 15.0.3`
- `retail_merchandising_system = 16.0.2`
- `retail_merchandising_system = 16.0.3`
- `retail_sales_audit = 14.1`
- `siebel_engineering_-_installer_&_deployment <= 2.20.5`
- `trace_file_analyzer = 12.2.0.1`
- `trace_file_analyzer = 18c`
- `trace_file_analyzer = 19c`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`
- `webcenter_sites = 12.2.1.3.0`
- `webcenter_sites = 12.2.1.4.0`
- `weblogic_server = 12.2.1.3.0`
- `weblogic_server = 12.2.1.4.0`
- `oncommand_workflow_automation`
- `steelstore_cloud_integrated_storage`

## Remediation

Upgrade past the affected range:

- `jackson-databind 2.9.10.1`
