7.5

CVE-2020-36518

Exploit

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FasterxmlJackson-databind Version < 2.12.6.1
FasterxmlJackson-databind Version >= 2.13.0 < 2.13.2.1
OracleCoherence Version14.1.1.0.0
OracleCommerce Platform Version11.3.0
OracleCommerce Platform Version11.3.1
OracleCommerce Platform Version11.3.2
OracleCommunications Billing And Revenue Management Version >= 12.0.0.4.0 <= 12.0.0.6.0
OracleFinancial Services Behavior Detection Platform Version >= 8.1.1.0 <= 8.1.2.1
OracleFinancial Services Enterprise Case Management Version >= 8.1.1.0 <= 8.1.2.1
OracleFinancial Services Trade-based Anti Money Laundering Version8.0.7 SwEditionenterprise
OracleFinancial Services Trade-based Anti Money Laundering Version8.0.8 SwEditionenterprise
OracleGlobal Lifecycle Management Opatch Version < 12.2.0.1.30
OracleGraph Server And Client Version < 22.2.0
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.14
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.13
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.18
OraclePrimavera Gateway Version >= 21.12.0 <= 21.12.1
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 17.12.0.0 <= 17.12.20.4
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 18.8.0.0 <= 18.8.25.4
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0 <= 19.12.19.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 21.12.4.0
OraclePrimavera Unifier Version >= 17.0 <= 17.12
OraclePrimavera Unifier Version18.0
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleRetail Sales Audit Version15.0.3.1
OracleSd-wan Edge Version9.0
OracleSd-wan Edge Version9.1
OracleSpatial Studio Version < 20.1.0
OracleUtilities Framework Version4.3.0.5.0
OracleUtilities Framework Version4.3.0.6.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleUtilities Framework Version4.4.0.5.0
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
DebianDebian Linux Version11.0
NetappActive Iq Unified Manager Version- SwPlatformlinux
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappOncommand Insight Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.685
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.