Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.
2018-12-20T17:29:00.910
2024-11-21T03:40:32.963
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fasterxml | jackson-modules-java8 | < 2.9.8 | Yes |
Application | oracle | clusterware | 12.1.0.2.0 | Yes |
Application | oracle | database_server | 12.1.0.2 | Yes |
Application | oracle | database_server | 12.2.0.1 | Yes |
Application | oracle | database_server | 18c | Yes |
Application | oracle | database_server | 19c | Yes |
Application | oracle | global_lifecycle_management_opatch | < 11.2.0.3.23 | Yes |
Application | oracle | global_lifecycle_management_opatch | < 12.2.0.1.19 | Yes |
Application | oracle | global_lifecycle_management_opatch | < 13.9.4.2.1 | Yes |
Application | oracle | nosql_database | < 19.3.12 | Yes |
Application | netapp | active_iq_unified_manager | ≥ 7.3 | Yes |
Application | netapp | active_iq_unified_manager | ≥ 7.3 | Yes |
Application | netapp | active_iq_unified_manager | ≥ 9.5 | Yes |