9.8

CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

Data is provided by the National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.0.0 < 2.6.7.3
FasterxmlJackson-databind Version >= 2.7.0 < 2.8.11.5
FasterxmlJackson-databind Version >= 2.9.0 < 2.9.10.1
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
FedoraprojectFedora Version30
FedoraprojectFedora Version31
OracleBanking Platform Version2.4.0
OracleBanking Platform Version2.4.1
OracleBanking Platform Version2.5.0
OracleBanking Platform Version2.6.0
OracleBanking Platform Version2.6.1
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.9.0
OracleCommunications Calendar Server Version8.0.0.2.0
OracleCommunications Calendar Server Version8.0.0.3.0
OracleGoldengate Application Adapters Version19.1.0.0.0
OraclePrimavera Gateway Version >= 17.7 <= 17.12.6
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.8
OraclePrimavera Gateway Version16.1
OraclePrimavera Gateway Version16.2
OraclePrimavera Gateway Version19.12.0
OracleRetail Sales Audit Version14.1
OracleTrace File Analyzer Version12.2.0.1
OracleTrace File Analyzer Version18c
OracleTrace File Analyzer Version19c
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
OracleWebcenter Sites Version12.2.1.3.0
OracleWebcenter Sites Version12.2.1.4.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
NetappActive Iq Unified Manager SwPlatformlinux Version >= 7.3
NetappActive Iq Unified Manager SwPlatformwindows Version >= 7.3
NetappActive Iq Unified Manager SwPlatformvmware_vsphere Version >= 9.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.84% 0.822
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://seclists.org/bugtraq/2019/Oct/6
Third Party Advisory
Mailing List
Issue Tracking
https://www.debian.org/security/2019/dsa-4542
Third Party Advisory
Mailing List