8.3

CVE-2021-20190

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fasterxml ≫ Jackson-databind Version < 2.6.7.5
Fasterxml ≫ Jackson-databind Version >= 2.7.0 < 2.9.10.7
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Oncommand Insight Version -
Apache ≫ Nifi Version >= 1.7.0 <= 1.12.1
Debian ≫ Debian Linux Version 9.0
Oracle ≫ Commerce Experience Manager Version 11.3.2
Oracle ≫ Commerce Guided Search Version 11.3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.48% 0.937
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 8.3 8.6 8.5
AV:N/AC:M/Au:N/C:P/I:P/A:C
CISA-ADP 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.oracle.com//security-alerts/cpujul2021.html
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1916633
Patch
Third Party Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20210219-0008/
Third Party Advisory
https://github.com/FasterXML/jackson-databind/issues/2854
Patch
Third Party Advisory
https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a%40%3Ccommits.nifi.apache.org%3E
Third Party Advisory
Mailing List