9.8

CVE-2019-17531

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.0.0 < 2.6.7.3
FasterxmlJackson-databind Version >= 2.7.0 < 2.8.11.5
FasterxmlJackson-databind Version >= 2.9.0 < 2.9.10.1
DebianDebian Linux Version8.0
RedhatJboss Enterprise Application Platform Version7.2
   RedhatEnterprise Linux Server Version6.0
   RedhatEnterprise Linux Server Version7.0
   RedhatEnterprise Linux Server Version8.0
RedhatJboss Enterprise Application Platform Version7.3
   RedhatEnterprise Linux Server Version6.0
   RedhatEnterprise Linux Server Version7.0
   RedhatEnterprise Linux Server Version8.0
OracleBanking Platform Version2.4.0
OracleBanking Platform Version2.4.1
OracleBanking Platform Version2.5.0
OracleBanking Platform Version2.6.0
OracleBanking Platform Version2.6.1
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.9.0
OracleCommunications Calendar Server Version8.0.0.2.0
OracleCommunications Calendar Server Version8.0.0.3.0
OracleGoldengate Application Adapters Version19.1.0.0.0
OraclePrimavera Gateway Version >= 17.7 <= 17.12.6
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.8
OraclePrimavera Gateway Version16.1
OraclePrimavera Gateway Version16.2
OraclePrimavera Gateway Version19.12.0
OracleRetail Sales Audit Version14.1
OracleTrace File Analyzer Version12.2.0.1
OracleTrace File Analyzer Version18c
OracleTrace File Analyzer Version19c
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
OracleWebcenter Sites Version12.2.1.3.0
OracleWebcenter Sites Version12.2.1.4.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.78
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.