VulnSea

goldengate_stream_analytics vulnerabilities

CVEs whose affected-version data names the goldengate_stream_analytics package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2019-14893Critical· 9.8
6y ago

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…

A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic ty…

▾ Midnightfasterxml · jackson-databindEPSS 4.1%via NVD
CVE-2019-20330Critical· 9.8
6y ago

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

▾ Midnightfasterxml · jackson-databindEPSS 8.6%via NVD
CVE-2019-16335Critical· 9.8
7y ago

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

▾ Midnightfasterxml · jackson-databindEPSS 5.0%via NVD
CVE-2019-14540Critical· 9.8PoC
7y ago

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

▾ Abyssalfasterxml · jackson-databindEPSS 11%via NVD
CVE-2019-14439High· 7.5PoC
7y ago

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service h…

▾ Midnightfasterxml · jackson-databindEPSS 11%via NVD
CVE-2019-14379Critical· 9.8
7y ago

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

▾ Midnightfasterxml · jackson-databindEPSS 8.1%via NVD
goldengate_stream_analytics vulnerabilities (CVEs) · VulnSea