CVE-2026-47022
- EPSS 0.14%
- Veröffentlicht 21.07.2026 21:33:05
- Zuletzt bearbeitet 06.08.2026 15:12:36
Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastruct...
CVE-2019-14893
- EPSS 4.09%
- Veröffentlicht 02.03.2020 21:15:17
- Zuletzt bearbeitet 21.11.2024 04:27:37
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling m...
CVE-2019-20330
- EPSS 8.64%
- Veröffentlicht 03.01.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:16
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-14540
- EPSS 10.76%
- Veröffentlicht 15.09.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:26:55
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
CVE-2019-16335
- EPSS 4.96%
- Veröffentlicht 15.09.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:32
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
CVE-2019-14439
- EPSS 10.85%
- Veröffentlicht 30.07.2019 11:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:44
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logbac...
CVE-2019-14379
- EPSS 8.11%
- Veröffentlicht 29.07.2019 12:15:16
- Zuletzt bearbeitet 21.11.2024 04:26:37
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CVE-2019-0201
- EPSS 9.71%
- Veröffentlicht 23.05.2019 14:29:07
- Zuletzt bearbeitet 21.11.2024 04:16:28
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field a...
CVE-2019-0222
- EPSS 12.03%
- Veröffentlicht 28.03.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:31
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
CVE-2018-8012
- EPSS 8.47%
- Veröffentlicht 21.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:05
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit cha...