VulnSea

siebel_engineering_-_installer_&_deployment vulnerabilities

CVEs whose affected-version data names the siebel_engineering_-_installer_&_deployment package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2020-5398High· 7.5PoC
6y ago

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in…

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in…

▾ Midnightvmware · spring_frameworkEPSS 89%via NVD
CVE-2019-20330Critical· 9.8
6y ago

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

▾ Midnightfasterxml · jackson-databindEPSS 8.6%via NVD
CVE-2019-17531Critical· 9.8
6y ago

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apa…

▾ Midnightfasterxml · jackson-databindEPSS 5.4%via NVD
CVE-2019-16942Critical· 9.8
7y ago

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the com…

▾ Midnightfasterxml · jackson-databindEPSS 5.7%via NVD
CVE-2019-16943Critical· 9.8
7y ago

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6s…

▾ Midnightfasterxml · jackson-databindEPSS 4.9%via NVD
CVE-2019-14439High· 7.5PoC
7y ago

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service h…

▾ Midnightfasterxml · jackson-databindEPSS 11%via NVD
CVE-2019-14379Critical· 9.8
7y ago

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

▾ Midnightfasterxml · jackson-databindEPSS 8.1%via NVD
CVE-2018-14718Critical· 9.8
7y ago

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

▾ Midnightfasterxml · jackson-databindEPSS 13%via NVD
siebel_engineering_-_installer_&_deployment vulnerabilities (CVEs) · VulnSea