8.1

CVE-2020-35728

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

Data is provided by the National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.9.0 < 2.9.10.8
DebianDebian Linux Version9.0
OracleAgile Plm Version9.3.6
OracleApplication Testing Suite Version13.3.0.1
OracleAutovue Version21.0.2
OracleBlockchain Platform Version <= 21.1.2
OracleCommerce Platform Version >= 11.3.0 <= 11.3.2
OracleCommerce Platform Version11.2.0
OracleCommunications Diameter Signaling Route Version >= 8.0.0.0 <= 8.5.0.0
OracleCommunications Element Manager Version >= 8.2.0.0 <= 8.2.4.0
OracleCommunications Session Report Manager Version >= 8.0.0.0 <= 8.2.2.1
OracleCommunications Session Route Manager Version >= 8.2.0.0 <= 8.2.2.1
OracleData Integrator Version12.2.1.4.0
OracleGoldengate Application Adapters Version19.1.0.0.0
OracleInsurance Policy Administration Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version >= 11.1.0 <= 11.3.0
OracleInsurance Rules Palette Version11.0.2
OracleJd Edwards Enterpriseone Tools Version < 9.2.5.3
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.11
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.10
OraclePrimavera Gateway Version20.12.0
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version >= 18.8 <= 19.12
OraclePrimavera Unifier Version20.12
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version16.0.3.0
OracleWebcenter Portal Version12.2.1.3.0
OracleWebcenter Portal Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 39.67% 0.972
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.