9.8

CVE-2018-19361

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.6.0 <= 2.6.7.2
FasterxmlJackson-databind Version >= 2.7.0 < 2.7.9.5
FasterxmlJackson-databind Version >= 2.8.0 < 2.8.11.3
FasterxmlJackson-databind Version >= 2.9.0 < 2.9.8
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OracleWebcenter Portal Version12.2.1.3.0
RedhatAutomation Manager Version7.3.1
RedhatDecision Manager Version7.3.1
RedhatJboss Bpm Suite Version6.4.11
RedhatJboss Brms Version6.4.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.06% 0.88
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://seclists.org/bugtraq/2019/May/68
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/107985
Third Party Advisory
VDB Entry
https://github.com/FasterXML/jackson-databind/issues/2186
Patch
Third Party Advisory
Issue Tracking
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8
Patch
Third Party Advisory
Release Notes
https://issues.apache.org/jira/browse/TINKERPOP-2121
Third Party Advisory
Issue Tracking