CVE-2020-10672
- EPSS 40.07%
- Published 18.03.2020 22:15:12
- Last modified 21.11.2024 04:55:49
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-9547
- EPSS 53.63%
- Published 02.03.2020 04:15:11
- Last modified 21.11.2024 05:40:50
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
CVE-2020-9548
- EPSS 70.37%
- Published 02.03.2020 04:15:11
- Last modified 21.11.2024 05:40:50
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
CVE-2020-9546
- EPSS 2.33%
- Published 02.03.2020 04:15:10
- Last modified 21.11.2024 05:40:50
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
CVE-2020-8840
- EPSS 8.16%
- Published 10.02.2020 21:56:10
- Last modified 21.11.2024 05:39:32
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
CVE-2019-20330
- EPSS 2%
- Published 03.01.2020 04:15:12
- Last modified 21.11.2024 04:38:16
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-3740
- EPSS 1.24%
- Published 18.09.2019 23:15:11
- Last modified 21.11.2024 04:42:26
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys...
CVE-2019-16335
- EPSS 0.74%
- Published 15.09.2019 22:15:10
- Last modified 21.11.2024 04:30:32
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
CVE-2019-14540
- EPSS 7.08%
- Published 15.09.2019 22:15:10
- Last modified 21.11.2024 04:26:55
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
CVE-2019-14439
- EPSS 9.41%
- Published 30.07.2019 11:15:11
- Last modified 21.11.2024 04:26:44
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logbac...