9.8

CVE-2017-7525

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

Data is provided by the National Vulnerability Database (NVD)
FasterxmlJackson-databind Version < 2.6.7.1
FasterxmlJackson-databind Version >= 2.7.0 < 2.7.9.1
FasterxmlJackson-databind Version >= 2.8.0 < 2.8.9
FasterxmlJackson-databind Version2.9.0 Updateprerelease1
FasterxmlJackson-databind Version2.9.0 Updateprerelease2
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
NetappOncommand Balance Version-
NetappOncommand Performance Manager Version- SwPlatformlinux
NetappOncommand Performance Manager Version- SwPlatformvmware_vsphere
NetappOncommand Shift Version-
NetappSnapcenter Version-
RedhatVirtualization Version4.0
   RedhatEnterprise Linux Server Version7.0
RedhatVirtualization Host Version4.0
   RedhatEnterprise Linux Server Version7.0
OracleBanking Platform Version2.5.0
OracleBanking Platform Version2.6.0
OracleBanking Platform Version2.6.1
OracleBanking Platform Version2.6.2
OraclePrimavera Unifier Version >= 17.1 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OracleWebcenter Portal Version12.2.1.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 77.34% 0.989
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-184 Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www.securitytracker.com/id/1039744
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040360
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/99623
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1039947
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1462702
Third Party Advisory
Issue Tracking
https://github.com/FasterXML/jackson-databind/issues/1599
Patch
Third Party Advisory
Issue Tracking