CVE-2019-20330
- EPSS 8.64%
- Veröffentlicht 03.01.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:16
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-17531
- EPSS 5.37%
- Veröffentlicht 12.10.2019 21:15:08
- Zuletzt bearbeitet 21.11.2024 04:32:27
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-ext...
CVE-2019-17267
- EPSS 4.63%
- Veröffentlicht 07.10.2019 00:15:10
- Zuletzt bearbeitet 07.10.2026 19:17:13
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
CVE-2019-16942
- EPSS 5.73%
- Veröffentlicht 01.10.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:23
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1....
CVE-2019-16943
- EPSS 4.9%
- Veröffentlicht 01.10.2019 17:15:10
- Zuletzt bearbeitet 07.10.2026 21:17:01
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) ja...
CVE-2019-16335
- EPSS 4.96%
- Veröffentlicht 15.09.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:32
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
CVE-2019-14540
- EPSS 10.76%
- Veröffentlicht 15.09.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:26:55
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
CVE-2019-14439
- EPSS 10.85%
- Veröffentlicht 30.07.2019 11:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:44
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logbac...
CVE-2019-14379
- EPSS 8.11%
- Veröffentlicht 29.07.2019 12:15:16
- Zuletzt bearbeitet 21.11.2024 04:26:37
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CVE-2018-11307
- EPSS 5.73%
- Veröffentlicht 09.07.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 03:43:06
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.