CVE-2020-35491High· 8.1▾ TwilightFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 1.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.5%
9.5% → 9.6%
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
jackson-databind >= 2.0.0, < 2.9.10.8service_level_managerdebian_linux = 9.0agile_product_lifecycle_management = 9.3.6application_testing_suite = 13.3.0.1autovue_for_agile_product_lifecycle_management = 21.0.2banking_platform = 2.6.2banking_platform = 2.7.0banking_platform = 2.7.1banking_platform = 2.8.0banking_platform = 2.9.0banking_platform = 2.10.0banking_treasury_management = 14.4banking_virtual_account_management = 14.2.0banking_virtual_account_management = 14.3.0banking_virtual_account_management = 14.5.0blockchain_platform <= 21.1.2communications_cloud_native_core_policy = 1.14.0communications_cloud_native_core_unified_data_repository = 1.4.0communications_diameter_signaling_route >= 8.0.0.0, <= 8.5.0.0communications_diameter_signaling_routecommunications_evolved_communications_application_server = 7.1communications_instant_messaging_server = 10.0.1.5.0communications_offline_mediation_controller = 12.0.0.3communications_pricing_design_center = 12.0.0.4.0communications_services_gatekeeper = 7.0communications_unified_inventory_management = 7.4.1documaker = 12.6.3documaker = 12.6.4insurance_policy_administration_j2ee = 11.0.2retail_customer_management_and_segmentation_foundation >= 16.0, <= 19.0retail_merchandising_system = 15.0.3retail_xstore_point_of_service = 16.0.6retail_xstore_point_of_service = 17.0.4retail_xstore_point_of_service = 18.0.3retail_xstore_point_of_service = 19.0.2sd-wan_edge = 9.0webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0Upgrade past the affected range:
jackson-databind 2.9.10.8Connected by shared product, vendor, weakness, or advisory.
CVE-2020-36182High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-35728High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/jav…
CVE-2020-14061High· 8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnect…
CVE-2021-20190High· 8.1A flaw was found in jackson-databind before 2.9.10.7
CVE-2020-36183High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
CVE-2020-36189High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.