9.8

CVE-2017-15095

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.0.0 < 2.6.7.2
FasterxmlJackson-databind Version >= 2.7.0 < 2.7.9.2
FasterxmlJackson-databind Version >= 2.8.0 < 2.8.10
FasterxmlJackson-databind Version2.9.0 Update-
FasterxmlJackson-databind Version2.9.0 Updateprerelease1
FasterxmlJackson-databind Version2.9.0 Updateprerelease2
FasterxmlJackson-databind Version2.9.0 Updateprerelease3
FasterxmlJackson-databind Version2.9.0 Updateprerelease4
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
RedhatSatellite Version6.4
RedhatSatellite Capsule Version6.4
RedhatOpenshift Container Platform Version4.1
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Application Platform Version6.0.0
   RedhatEnterprise Linux Version5.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Application Platform Version6.4.0
   RedhatEnterprise Linux Version5.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Application Platform Version7.1.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
NetappOncommand Balance Version-
NetappOncommand Performance Manager Version- SwPlatformlinux
NetappOncommand Performance Manager Version- SwPlatformvmware_vsphere
NetappOncommand Shift Version-
NetappSnapcenter Version-
OracleBanking Platform Version2.5.0
OracleBanking Platform Version2.6.0
OracleBanking Platform Version2.6.1
OracleBanking Platform Version2.6.2
OracleClusterware Version12.1.0.2.0
OracleDatabase Server Version12.2.0.1
OracleDatabase Server Version18.1
OracleIdentity Manager Version11.1.2.3.0
OracleIdentity Manager Version12.2.1.3.0
OraclePrimavera Unifier Version >= 17.1 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OracleWebcenter Portal Version12.2.1.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.41% 0.914
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-184 Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www.securityfocus.com/bid/103880
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1039769
Third Party Advisory
VDB Entry
https://github.com/FasterXML/jackson-databind/issues/1737
Patch
Third Party Advisory
Issue Tracking