CVE-2020-14060
- EPSS 8.61%
- Veröffentlicht 14.06.2020 21:15:09
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
CVE-2020-14061
- EPSS 4.46%
- Veröffentlicht 14.06.2020 20:15:10
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, o...
CVE-2020-14062
- EPSS 8.07%
- Veröffentlicht 14.06.2020 20:15:10
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
- EPSS 56.64%
- Veröffentlicht 20.05.2020 19:15:09
- Zuletzt bearbeitet 25.08.2026 16:28:27
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the Persiste...
CVE-2020-10683
- EPSS 7.27%
- Veröffentlicht 01.05.2020 19:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any a...
CVE-2020-2920
- EPSS 1.13%
- Veröffentlicht 15.04.2020 14:15:35
- Zuletzt bearbeitet 08.05.2025 18:13:51
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). Supported versions that are affected are 9.3.3, 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP...
CVE-2020-11619
- EPSS 3.61%
- Veröffentlicht 07.04.2020 23:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
CVE-2020-11111
- EPSS 3.58%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112
- EPSS 3.67%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113
- EPSS 6.28%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).