A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
2021-01-19T17:15:13.427
2024-11-21T05:46:05.973
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:C
8.6
8.5
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fasterxml | jackson-databind | < 2.6.7.5 | Yes |
Application | fasterxml | jackson-databind | < 2.9.10.7 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | oncommand_api_services | - | Yes |
Application | netapp | oncommand_insight | - | Yes |
Application | netapp | service_level_manager | - | Yes |
Application | apache | nifi | ≤ 1.12.1 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Application | oracle | commerce_guided_search_and_experience_manager | 11.3.2 | Yes |