8.1
CVE-2020-24750
- EPSS 2.11%
- Published 17.09.2020 19:15:13
- Last modified 21.11.2024 05:16:00
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Data is provided by the National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version >= 2.0.0 < 2.6.7.5
Fasterxml ≫ Jackson-databind Version >= 2.7.0 < 2.9.10.6
Oracle ≫ Application Testing Suite Version13.3.0.1
Oracle ≫ Autovue For Agile Product Lifecycle Management Version21.0.2
Oracle ≫ Banking Corporate Lending Process Management Version14.2.0
Oracle ≫ Banking Corporate Lending Process Management Version14.3.0
Oracle ≫ Banking Corporate Lending Process Management Version14.5.0
Oracle ≫ Banking Credit Facilities Process Management Version14.2.0
Oracle ≫ Banking Credit Facilities Process Management Version14.3.0
Oracle ≫ Banking Credit Facilities Process Management Version14.5.0
Oracle ≫ Banking Liquidity Management Version14.2
Oracle ≫ Banking Liquidity Management Version14.3
Oracle ≫ Banking Liquidity Management Version14.5
Oracle ≫ Banking Supply Chain Finance Version14.2.0
Oracle ≫ Banking Supply Chain Finance Version14.3.0
Oracle ≫ Banking Supply Chain Finance Version14.5.0
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Communications Calendar Server Version8.0
Oracle ≫ Communications Calendar Server Version8.0.0.4.0
Oracle ≫ Communications Contacts Server Version8.0
Oracle ≫ Communications Contacts Server Version8.0.0.5.0
Oracle ≫ Communications Diameter Signaling Router Version >= 8.0.0 <= 8.2.2
Oracle ≫ Communications Element Manager Version >= 8.2.0 <= 8.2.4.0
Oracle ≫ Communications Instant Messaging Server Version10.0.1.5.0
Oracle ≫ Communications Messaging Server Version8.1
Oracle ≫ Communications Offline Mediation Controller Version12.0.0.3.0
Oracle ≫ Communications Policy Management Version12.5.0
Oracle ≫ Communications Pricing Design Center Version12.0.0.4.0
Oracle ≫ Communications Services Gatekeeper Version7.0
Oracle ≫ Communications Session Report Manager Version >= 8.0.0.0 <= 8.2.2.1
Oracle ≫ Communications Session Route Manager Version >= 8.2.0 <= 8.2.2.1
Oracle ≫ Communications Unified Inventory Management Version7.4.1
Oracle ≫ Identity Manager Connector Version11.1.1.5.0
Oracle ≫ Siebel Core - Server Framework Version <= 21.5
Oracle ≫ Siebel Ui Framework Version <= 21.2
Debian ≫ Debian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.11% | 0.825 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.