8.1

CVE-2020-35491

Exploit

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

Data is provided by the National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.0.0 < 2.9.10.8
DebianDebian Linux Version9.0
OracleAgile Plm Version9.3.6
OracleApplication Testing Suite Version13.3.0.1
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.8.0
OracleBanking Platform Version2.9.0
OracleBanking Platform Version2.10.0
OracleBlockchain Platform Version <= 21.1.2
OracleCommunications Diameter Signaling Route Version >= 8.0.0.0 <= 8.5.0.0
OracleDocumaker Version12.6.3
OracleDocumaker Version12.6.4
OracleSd-wan Edge Version9.0
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.06% 0.918
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.