9.8
CVE-2018-19361
- EPSS 4.06%
- Veröffentlicht 02.01.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:48
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version >= 2.6.0 <= 2.6.7.2
Fasterxml ≫ Jackson-databind Version >= 2.7.0 < 2.7.9.5
Fasterxml ≫ Jackson-databind Version >= 2.8.0 < 2.8.11.3
Fasterxml ≫ Jackson-databind Version >= 2.9.0 < 2.9.8
Debian ≫ Debian Linux Version8.0
Debian ≫ Debian Linux Version9.0
Oracle ≫ Business Process Management Suite Version12.1.3.0.0
Oracle ≫ Business Process Management Suite Version12.2.1.3.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 17.7 <= 17.12
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version15.1
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version15.2
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version16.1
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version16.2
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version18.8
Oracle ≫ Primavera Unifier Version >= 17.7 <= 17.12
Oracle ≫ Primavera Unifier Version16.1
Oracle ≫ Primavera Unifier Version16.2
Oracle ≫ Primavera Unifier Version18.8
Oracle ≫ Retail Workforce Management Software Version1.60.9.0.0
Oracle ≫ Webcenter Portal Version12.2.1.3.0
Redhat ≫ Automation Manager Version7.3.1
Redhat ≫ Decision Manager Version7.3.1
Redhat ≫ Jboss Bpm Suite Version6.4.11
Redhat ≫ Jboss Brms Version6.4.10
Redhat ≫ Openshift Container Platform Version3.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 4.06% | 0.88 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.