9.8
CVE-2017-7525
- EPSS 37.72%
- Veröffentlicht 06.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:04
- Erkennungen
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version < 2.6.7.1
Fasterxml ≫ Jackson-databind Version >= 2.7.0 < 2.7.9.1
Fasterxml ≫ Jackson-databind Version >= 2.8.0 < 2.8.9
Fasterxml ≫ Jackson-databind Version 2.9.0 Update prerelease1
Fasterxml ≫ Jackson-databind Version 2.9.0 Update prerelease2
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Netapp ≫ Oncommand Balance Version -
Netapp ≫ Oncommand Performance Manager Version - SwPlatform linux
Netapp ≫ Oncommand Performance Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Oncommand Shift Version -
Netapp ≫ Snapcenter Version -
Redhat ≫ Openshift Container Platform Version 4.1
Redhat ≫ Virtualization Version 4.0
Redhat ≫ Virtualization Host Version 4.0
Redhat ≫ Jboss Enterprise Application Platform Version 6.0.0
Redhat ≫ Jboss Enterprise Application Platform Version 6.4.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.1
Redhat ≫ Jboss Enterprise Application Platform Version 6.0.0
Redhat ≫ Jboss Enterprise Application Platform Version 6.4.0
Redhat ≫ Openshift Container Platform Version 3.11
Oracle ≫ Banking Platform Version 2.5.0
Oracle ≫ Banking Platform Version 2.6.0
Oracle ≫ Banking Platform Version 2.6.1
Oracle ≫ Banking Platform Version 2.6.2
Oracle ≫ Communications Billing And Revenue Management Version 7.5
Oracle ≫ Communications Billing And Revenue Management Version 12.0
Oracle ≫ Communications Communications Policy Management Version >= 12.0 <= 12.5.2
Oracle ≫ Communications Diameter Signaling Route Version < 8.3
Oracle ≫ Communications Instant Messaging Server Version 10.0.1
Oracle ≫ Communications Instant Messaging Server Version 10.0.1.2.0
Oracle ≫ Enterprise Manager For Virtualization Version 13.2.2
Oracle ≫ Enterprise Manager For Virtualization Version 13.2.3
Oracle ≫ Enterprise Manager For Virtualization Version 13.3.1
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.0.2.0.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.0.3.0.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.0.4.0.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.0.5.0.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.0.6.0.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version 8.0.7.0.0
Oracle ≫ Global Lifecycle Management Opatchauto Version < 12.2.0.1.14
Oracle ≫ Primavera Unifier Version >= 17.1 <= 17.12
Oracle ≫ Primavera Unifier Version 16.1
Oracle ≫ Primavera Unifier Version 16.2
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Utilities Advanced Spatial And Operational Analytics Version 2.7.0.1
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 37.72% | 0.984 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-184 Incomplete List of Disallowed Inputs
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://access.redhat.com/errata/RHSA-2019:0910
https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://access.redhat.com/errata/RHSA-2017:3454
https://access.redhat.com/errata/RHSA-2017:3455
https://access.redhat.com/errata/RHSA-2017:3456
https://access.redhat.com/errata/RHSA-2017:3458
https://access.redhat.com/errata/RHSA-2017:1834
https://access.redhat.com/errata/RHSA-2017:1835
https://access.redhat.com/errata/RHSA-2017:1836
https://access.redhat.com/errata/RHSA-2017:1837
https://access.redhat.com/errata/RHSA-2018:1449
https://access.redhat.com/errata/RHSA-2018:1450
https://access.redhat.com/errata/RHSA-2017:2633
https://access.redhat.com/errata/RHSA-2017:2635
https://access.redhat.com/errata/RHSA-2017:2636
https://access.redhat.com/errata/RHSA-2017:2637
https://access.redhat.com/errata/RHSA-2017:2638
https://access.redhat.com/errata/RHSA-2017:2546
https://access.redhat.com/errata/RHSA-2017:2547
http://www.securitytracker.com/id/1039744
http://www.securitytracker.com/id/1040360
https://access.redhat.com/errata/RHSA-2017:3141
https://access.redhat.com/errata/RHSA-2018:0294
https://access.redhat.com/errata/RHSA-2017:2477
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
https://lists.apache.org/thread.html/4641ed8616ccc2c1fbddac2c3dc9900c96387bc226eaf0232d61909b%40%3Ccommits.cassandra.apache.org%3E
https://lists.apache.org/thread.html/r42ac3e39e6265db12d9fc6ae1cd4b5fea7aed9830dc6f6d58228fed7%40%3Ccommits.cassandra.apache.org%3E
https://lists.apache.org/thread.html/rf7f87810c38dc9abf9f93989f76008f504cbf7c1a355214640b2d04c%40%3Ccommits.cassandra.apache.org%3E
https://access.redhat.com/errata/RHSA-2018:0342
https://access.redhat.com/errata/RHSA-2019:2858
https://access.redhat.com/errata/RHSA-2019:3149
https://lists.apache.org/thread.html/f095a791bda6c0595f691eddd0febb2d396987eec5cbd29120d8c629%40%3Csolr-user.lucene.apache.org%3E
https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html
http://www.securityfocus.com/bid/99623
http://www.securitytracker.com/id/1039947
https://access.redhat.com/errata/RHSA-2017:1839
https://access.redhat.com/errata/RHSA-2017:1840
https://bugzilla.redhat.com/show_bug.cgi?id=1462702
https://cwiki.apache.org/confluence/display/WW/S2-055
https://github.com/FasterXML/jackson-databind/issues/1599
https://github.com/FasterXML/jackson-databind/issues/1723
https://lists.apache.org/thread.html/3c87dc8bca99a2b3b4743713b33d1de05b1d6b761fdf316224e9c81f%40%3Cdev.lucene.apache.org%3E
https://lists.apache.org/thread.html/5008bcbd45ee65ce39e4220b6ac53d28a24d6bc67d5804e9773a7399%40%3Csolr-user.lucene.apache.org%3E
https://lists.apache.org/thread.html/b1f33fe5ade396bb903fdcabe9f243f7692c7dfce5418d3743c2d346%40%3Cdev.lucene.apache.org%3E
https://lists.apache.org/thread.html/c10a2bf0fdc3d25faf17bd191d6ec46b29a353fa9c97bebd7c4e5913%40%3Cdev.lucene.apache.org%3E
https://lists.apache.org/thread.html/c2ed4c0126b43e324cf740012a0edd371fd36096fd777be7bfe7a2a6%40%3Cdev.lucene.apache.org%3E
https://lists.apache.org/thread.html/c9d5ff20929e8a3c8794facf4c4b326a9c10618812eec356caa20b87%40%3Csolr-user.lucene.apache.org%3E
https://lists.apache.org/thread.html/f60afd3c7e9ebaaf70fad4a4beb75cf8740ac959017a31e7006c7486%40%3Cdev.lucene.apache.org%3E
https://lists.apache.org/thread.html/r68acf97f4526ba59a33cc6e592261ea4f85d890f99e79c82d57dd589%40%3Cissues.spark.apache.org%3E
https://lists.debian.org/debian-lts-announce/2020/08/msg00039.html
https://security.netapp.com/advisory/ntap-20171214-0002/
https://www.debian.org/security/2017/dsa-4004