7.5

CVE-2020-36518

Exploit
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version < 2.12.6.1
Fasterxml ≫ Jackson-databind Version >= 2.13.0 < 2.13.2.1
Oracle ≫ Coherence Version 14.1.1.0.0
Oracle ≫ Commerce Platform Version 11.3.0
Oracle ≫ Commerce Platform Version 11.3.1
Oracle ≫ Commerce Platform Version 11.3.2
Oracle ≫ Communications Billing And Revenue Management Version >= 12.0.0.4.0 <= 12.0.0.6.0
Oracle ≫ Financial Services Behavior Detection Platform Version >= 8.1.1.0 <= 8.1.2.1
Oracle ≫ Financial Services Enterprise Case Management Version >= 8.1.1.0 <= 8.1.2.1
Oracle ≫ Financial Services Trade-based Anti Money Laundering Version 8.0.7 SwEdition enterprise
Oracle ≫ Financial Services Trade-based Anti Money Laundering Version 8.0.8 SwEdition enterprise
Oracle ≫ Global Lifecycle Management Opatch Version < 12.2.0.1.30
Oracle ≫ Graph Server And Client Version < 22.2.0
Oracle ≫ Health Sciences Empirica Signal Version 9.1.0.5.2
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.11
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.14
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.13
Oracle ≫ Primavera Gateway Version >= 20.12.0 <= 20.12.18
Oracle ≫ Primavera Gateway Version >= 21.12.0 <= 21.12.1
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 17.12.0.0 <= 17.12.20.4
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 18.8.0.0 <= 18.8.25.4
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 19.12.0 <= 19.12.19.0
Oracle ≫ Primavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 21.12.4.0
Oracle ≫ Primavera Unifier Version >= 17.0 <= 17.12
Oracle ≫ Primavera Unifier Version 18.0
Oracle ≫ Primavera Unifier Version 19.12
Oracle ≫ Primavera Unifier Version 20.12
Oracle ≫ Primavera Unifier Version 21.12
Oracle ≫ Retail Sales Audit Version 15.0.3.1
Oracle ≫ Sd-wan Edge Version 9.0
Oracle ≫ Sd-wan Edge Version 9.1
Oracle ≫ Spatial Studio Version < 20.1.0
Oracle ≫ Utilities Framework Version 4.3.0.5.0
Oracle ≫ Utilities Framework Version 4.3.0.6.0
Oracle ≫ Utilities Framework Version 4.4.0.0.0
Oracle ≫ Utilities Framework Version 4.4.0.2.0
Oracle ≫ Utilities Framework Version 4.4.0.3.0
Oracle ≫ Utilities Framework Version 4.4.0.5.0
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Oncommand Insight Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.86% 0.909
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.oracle.com/security-alerts/cpuapr2022.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
Third Party Advisory
https://github.com/FasterXML/jackson-databind/issues/2816
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html
Third Party Advisory
Exploit
Mailing List
https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20220506-0004/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5283
Third Party Advisory