Fasterxml

Jackson-databind

87 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.22%
  • Veröffentlicht 06.01.2021 23:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.

Exploit
  • EPSS 5.2%
  • Veröffentlicht 06.01.2021 23:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.

Exploit
  • EPSS 10.91%
  • Veröffentlicht 06.01.2021 23:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

Exploit
  • EPSS 4.91%
  • Veröffentlicht 06.01.2021 23:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.

Exploit
  • EPSS 5.02%
  • Veröffentlicht 06.01.2021 23:15:12
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.

  • EPSS 12.5%
  • Veröffentlicht 27.12.2020 05:15:11
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.js...

Exploit
  • EPSS 9.48%
  • Veröffentlicht 17.12.2020 19:15:14
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

Exploit
  • EPSS 7.69%
  • Veröffentlicht 17.12.2020 19:15:14
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

  • EPSS 17.61%
  • Veröffentlicht 03.12.2020 17:15:12
  • Zuletzt bearbeitet 25.08.2026 16:28:27

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

  • EPSS 7.33%
  • Veröffentlicht 17.09.2020 19:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.