9.8

CVE-2018-14720

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version >= 2.6.0 < 2.6.7.2
Fasterxml ≫ Jackson-databind Version >= 2.7.0 < 2.7.9.5
Fasterxml ≫ Jackson-databind Version >= 2.8.0 < 2.8.11.3
Fasterxml ≫ Jackson-databind Version >= 2.9.0 < 2.9.7
Fasterxml ≫ Jackson-databind Version 2.7.0 Update rc1
Fasterxml ≫ Jackson-databind Version 2.7.0 Update rc2
Fasterxml ≫ Jackson-databind Version 2.7.0 Update rc3
Fasterxml ≫ Jackson-databind Version 2.8.0 Update rc1
Fasterxml ≫ Jackson-databind Version 2.8.0 Update rc2
Fasterxml ≫ Jackson-databind Version 2.9.0 Update pr1
Fasterxml ≫ Jackson-databind Version 2.9.0 Update pr2
Fasterxml ≫ Jackson-databind Version 2.9.0 Update pr3
Fasterxml ≫ Jackson-databind Version 2.9.0 Update pr4
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Oracle ≫ Banking Platform Version 2.5.0
Oracle ≫ Banking Platform Version 2.6.0
Oracle ≫ Banking Platform Version 2.6.1
Oracle ≫ Banking Platform Version 2.6.2
Oracle ≫ Jdeveloper Version 12.1.3.0.0
Oracle ≫ Jdeveloper Version 12.2.1.3.0
Oracle ≫ Primavera Unifier Version >= 17.1 <= 17.12
Oracle ≫ Primavera Unifier Version 16.1
Oracle ≫ Primavera Unifier Version 16.2
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.52% 0.937
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Patch
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
https://access.redhat.com/errata/RHSA-2019:2858
https://access.redhat.com/errata/RHSA-2019:3149
https://access.redhat.com/errata/RHSA-2019:3892
https://access.redhat.com/errata/RHSA-2019:1106
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1107
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1140
Third Party Advisory
https://access.redhat.com/errata/RHBA-2019:0959
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0782
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1822
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1823
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4037
https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44
Patch
Third Party Advisory
https://github.com/FasterXML/jackson-databind/issues/2097
Patch
Third Party Advisory
Issue Tracking
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7
Patch
Third Party Advisory
Release Notes
https://lists.apache.org/thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286%40%3Cdev.lucene.apache.org%3E
https://lists.apache.org/thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f%40%3Cdev.lucene.apache.org%3E
https://lists.apache.org/thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df%40%3Cdev.lucene.apache.org%3E
https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html
Third Party Advisory
https://seclists.org/bugtraq/2019/May/68
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20190530-0003/
Third Party Advisory
https://www.debian.org/security/2019/dsa-4452
Third Party Advisory