9.8

CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version >= 2.0.0 < 2.6.7.3
Fasterxml ≫ Jackson-databind Version >= 2.7.0 < 2.8.11.5
Fasterxml ≫ Jackson-databind Version >= 2.9.0 < 2.9.10.1
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Oracle ≫ Banking Platform Version 2.4.0
Oracle ≫ Banking Platform Version 2.4.1
Oracle ≫ Banking Platform Version 2.5.0
Oracle ≫ Banking Platform Version 2.6.0
Oracle ≫ Banking Platform Version 2.6.1
Oracle ≫ Banking Platform Version 2.6.2
Oracle ≫ Banking Platform Version 2.7.0
Oracle ≫ Banking Platform Version 2.7.1
Oracle ≫ Banking Platform Version 2.9.0
Oracle ≫ Communications Calendar Server Version 8.0.0.2.0
Oracle ≫ Communications Calendar Server Version 8.0.0.3.0
Oracle ≫ Goldengate Application Adapters Version 19.1.0.0.0
Oracle ≫ Primavera Gateway Version >= 17.7 <= 17.12.6
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.8
Oracle ≫ Primavera Gateway Version 16.1
Oracle ≫ Primavera Gateway Version 16.2
Oracle ≫ Primavera Gateway Version 19.12.0
Oracle ≫ Retail Merchandising System Version 15.0.3
Oracle ≫ Retail Merchandising System Version 16.0.2
Oracle ≫ Retail Merchandising System Version 16.0.3
Oracle ≫ Retail Sales Audit Version 14.1
Oracle ≫ Trace File Analyzer Version 12.2.0.1
Oracle ≫ Trace File Analyzer Version 18c
Oracle ≫ Trace File Analyzer Version 19c
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Oracle ≫ Webcenter Portal Version 12.2.1.4.0
Oracle ≫ Webcenter Sites Version 12.2.1.3.0
Oracle ≫ Webcenter Sites Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Netapp ≫ Active Iq Unified Manager SwPlatform linux Version >= 7.3
Netapp ≫ Active Iq Unified Manager SwPlatform windows Version >= 7.3
Netapp ≫ Active Iq Unified Manager SwPlatform vmware_vsphere Version >= 9.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.9% 0.911
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.oracle.com/security-alerts/cpujan2020.html
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062
https://www.debian.org/security/2019/dsa-4542
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20191017-0006/
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0159
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0160
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0161
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0164
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0445
Third Party Advisory
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f%40%3Ccommits.druid.apache.org%3E
https://github.com/FasterXML/jackson-databind/issues/2478
Patch
Third Party Advisory
https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd%40%3Ccommits.iceberg.apache.org%3E
https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6%40%3Cissues.iceberg.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/
https://seclists.org/bugtraq/2019/Oct/6
Third Party Advisory
Mailing List
Issue Tracking