VulnSea

utilities_advanced_spatial_and_operational_analytics vulnerabilities

CVEs whose affected-version data names the utilities_advanced_spatial_and_operational_analytics package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2018-11307Critical· 9.8
7y ago

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5

An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

▾ Midnightfasterxml · jackson-databindEPSS 5.7%via NVD
CVE-2017-7525Critical· 9.8PoC
8y ago

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue meth…

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue meth…

▾ Abyssalfasterxml · jackson-databindEPSS 38%via NVD
CVE-2017-15095Critical· 9.8
8y ago

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of th…

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of th…

▾ Midnightfasterxml · jackson-databindEPSS 8.4%via NVD
utilities_advanced_spatial_and_operational_analytics vulnerabilities (CVEs) · VulnSea