An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
2019-03-21T16:00:12.407
2024-11-21T03:44:26.187
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:H/Au:N/C:P/I:P/A:P
4.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fasterxml | jackson-databind | < 2.7.9.4 | Yes |
Application | fasterxml | jackson-databind | < 2.8.11.2 | Yes |
Application | fasterxml | jackson-databind | < 2.9.6 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | fedoraproject | fedora | 29 | Yes |
Application | oracle | jd_edwards_enterpriseone_tools | 9.2 | Yes |
Application | oracle | retail_merchandising_system | 15.0 | Yes |
Application | redhat | automation_manager | 7.3.1 | Yes |
Application | redhat | decision_manager | 7.3.1 | Yes |
Application | redhat | jboss_brms | 6.4.10 | Yes |
Application | redhat | jboss_enterprise_application_platform | 7.2.0 | Yes |
Application | redhat | openshift_container_platform | 3.11 | Yes |
Application | redhat | single_sign-on | 7.3 | Yes |