An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
2019-07-09T16:15:12.807
2024-11-21T03:43:06.380
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fasterxml | jackson-databind | < 2.6.7.3 | Yes |
Application | fasterxml | jackson-databind | < 2.7.9.4 | Yes |
Application | fasterxml | jackson-databind | < 2.8.11.2 | Yes |
Application | fasterxml | jackson-databind | < 2.9.6 | Yes |
Application | redhat | openshift_container_platform | 3.11 | Yes |
Application | redhat | openshift_container_platform | 4.1 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | No |
Application | oracle | clusterware | 12.1.0.2.0 | Yes |
Application | oracle | communications_instant_messaging_server | 10.0.1.2.0 | Yes |
Application | oracle | global_lifecycle_management_opatch | < 11.2.0.3.23 | Yes |
Application | oracle | global_lifecycle_management_opatch | < 12.2.0.1.19 | Yes |
Application | oracle | global_lifecycle_management_opatch | < 13.9.4.2.1 | Yes |
Application | oracle | retail_customer_management_and_segmentation_foundation | 17.0 | Yes |
Application | oracle | utilities_advanced_spatial_and_operational_analytics | 2.7.0.1 | Yes |