9.8

CVE-2019-14379

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

Data is provided by the National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.0.0 < 2.6.7.3
FasterxmlJackson-databind Version >= 2.7.0 < 2.7.9.6
FasterxmlJackson-databind Version >= 2.8.0 < 2.8.11.4
FasterxmlJackson-databind Version >= 2.9.0 < 2.9.9.2
DebianDebian Linux Version8.0
NetappActive Iq Unified Manager SwPlatformlinux Version >= 7.3
NetappActive Iq Unified Manager SwPlatformwindows Version >= 7.3
NetappActive Iq Unified Manager SwPlatformvmware_vsphere Version >= 9.5
NetappSnapcenter Version-
FedoraprojectFedora Version29
FedoraprojectFedora Version30
FedoraprojectFedora Version31
RedhatOpenshift Container Platform Version4.1
   RedhatEnterprise Linux Version7.0
RedhatSingle Sign-on Version7.3
   RedhatEnterprise Linux Version7.0
RedhatSingle Sign-on Version7.3
   RedhatEnterprise Linux Version6.0
RedhatSingle Sign-on Version7.3
   RedhatEnterprise Linux Version8.0
OracleBanking Platform Version2.4.0
OracleBanking Platform Version2.4.1
OracleBanking Platform Version2.5.0
OracleBanking Platform Version2.6.0
OracleBanking Platform Version2.6.1
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleGoldengate Stream Analytics Version < 19.1.0.0.1
OraclePrimavera Gateway Version15.2
OraclePrimavera Gateway Version16.2
OraclePrimavera Gateway Version17.12
OraclePrimavera Gateway Version18.8.0
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OracleSiebel Ui Framework Version <= 19.10
AppleXCode Version < 13.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.46% 0.8
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

http://seclists.org/fulldisclosure/2022/Mar/23
Third Party Advisory
Mailing List
https://github.com/FasterXML/jackson-databind/issues/2387
Patch
Third Party Advisory
Issue Tracking