CVE-2020-25649High· 7.5▾ TwilightA flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 3.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
18%
18% → 18%
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
jackson-databind >= 2.6.0, < 2.6.7.4jackson-databind >= 2.9.0, < 2.9.10.7jackson-databind >= 2.10.0, < 2.10.5.1oncommand_api_servicesoncommand_workflow_automationservice_level_managerfedora = 32quarkus <= 1.6.1iotdb < 0.12.0agile_product_lifecycle_management = 9.3.6agile_product_lifecycle_management_integration_pack = 3.6banking_apis >= 18.1, <= 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_platform = 2.6.2banking_platform = 2.7.0banking_platform = 2.7.1banking_platform = 2.8.0banking_platform = 2.9.0banking_platform = 2.10.0banking_treasury_management = 4.4blockchain_platform < 21.1.2coherence = 12.2.1.4.0coherence = 14.1.1.0.0commerce_platform >= 11.3.0, <= 11.3.2commerce_platform = 11.2.0communications_billing_and_revenue_management = 7.5.0.23.0communications_billing_and_revenue_management = 12.0.0.3.0communications_cloud_native_core_unified_data_repository = 1.4.0communications_convergent_charging_controller = 12.0.4.0.0communications_evolved_communications_application_server = 7.1communications_instant_messaging_server = 10.0.1.5.0communications_interactive_session_recorder = 6.3communications_interactive_session_recorder = 6.4communications_network_charging_and_control = 12.0.4.0.0communications_offline_mediation_controller = 12.0.0.3communications_pricing_design_center = 12.0.0.4.0communications_services_gatekeeper = 7.0communications_unified_inventory_management = 7.4.1goldengate_application_adapters = 19.1.0.0.0health_sciences_empirica_signal = 9.0health_sciences_empirica_signal = 9.1insurance_policy_administration >= 11.1.0, <= 11.3.0insurance_policy_administration = 11.0.2insurance_rules_palette >= 11.1.0, <= 11.3.0insurance_rules_palette = 11.0.2jd_edwards_enterpriseone_orchestrator < 9.2.5.3jd_edwards_enterpriseone_tools < 9.2.5.3primavera_gateway >= 17.7, <= 17.12primavera_gateway >= 17.12.0, <= 17.12.11primavera_gateway >= 18.8.0, <= 18.8.11primavera_gateway >= 19.12.0, <= 19.12.10primavera_gateway = 20.12.0retail_service_backbone = 14.1.3.2retail_service_backbone = 15.0.3.1retail_service_backbone = 16.0.3retail_xstore_point_of_service = 16.0.6retail_xstore_point_of_service = 17.0.4retail_xstore_point_of_service = 18.0.3retail_xstore_point_of_service = 19.0.2retail_xstore_point_of_service = 20.0.1sd-wan_edge = 9.0utilities_framework = 4.3.0.5.0utilities_framework = 4.3.0.6.0utilities_framework = 4.4.0.0.0utilities_framework = 4.4.0.2.0utilities_framework = 4.4.0.3.0webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0communications_messaging_server = 8.0.2communications_messaging_server = 8.1Upgrade past the affected range:
jackson-databind 2.10.5.1iotdb 0.12.0blockchain_platform 21.1.2jd_edwards_enterpriseone_orchestrator 9.2.5.3jd_edwards_enterpriseone_tools 9.2.5.3Connected by shared product, vendor, weakness, or advisory.
CVE-2020-36183High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
CVE-2020-36182High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36189High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
CVE-2020-36188High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
CVE-2020-36187High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
CVE-2020-36186High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.