CVE-2020-9547Critical· 9.8▾ AbyssalPoC availableFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 3.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
18%
1 GitHub repo · Nuclei ×1 (last check)
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
jackson-databind >= 2.0.0, < 2.7.9.7jackson-databind >= 2.8.0, < 2.8.11.6jackson-databind >= 2.9.0, < 2.9.10.4active_iq_unified_manager >= 7.3active_iq_unified_manager >= 9.5debian_linux = 8.0autovue_for_agile_product_lifecycle_management = 21.0.2banking_platform >= 2.4.0, <= 2.9.0communications_contacts_server = 8.0.0.4.0communications_evolved_communications_application_server = 7.1communications_instant_messaging_server = 10.0.1.4.0communications_network_charging_and_control >= 12.0.0, <= 12.0.3communications_network_charging_and_control = 6.0.1enterprise_manager_base_platform = 13.3.0.0enterprise_manager_base_platform = 13.4.0.0global_lifecycle_management_opatch < 12.2.0.1.20jd_edwards_enterpriseone_orchestrator < 9.2.4.2jd_edwards_enterpriseone_tools < 9.2.4.2primavera_unifier >= 17.7, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8primavera_unifier = 19.12retail_xstore_point_of_service = 15.0retail_xstore_point_of_service = 16.0retail_xstore_point_of_service = 17.0retail_xstore_point_of_service = 18.0retail_xstore_point_of_service = 19.0weblogic_server = 12.2.1.3.0weblogic_server = 12.2.1.4.0Upgrade past the affected range:
jackson-databind 2.9.10.4global_lifecycle_management_opatch 12.2.0.1.20jd_edwards_enterpriseone_orchestrator 9.2.4.2jd_edwards_enterpriseone_tools 9.2.4.2Connected by shared product, vendor, weakness, or advisory.
CVE-2020-35728High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/jav…
CVE-2020-11113High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-14061High· 8.1FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnect…
CVE-2020-11112High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11111High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-10969High· 8.8FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.