A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jackson-databindUpgrade libjackson-json-java | Oct 20, 2017 | Oct 20, 2017 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 27419391 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 27395085 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 27338939 for version 12.2.1.2.0.Apply the Patch Set Update (PSU) 27342434 for version 12.2.1.3.0. | Apr 18, 2018 | Feb 6, 2018 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jul 14, 2017 |
| Red_hat Jboss_eap | — | — | Nov 14, 2019 | Feb 6, 2018 |
| Redhat Openshift | — | Upgrade logging | Oct 8, 2019 | Feb 6, 2018 |
| Struts | — | Upgrade to Apache Struts version 2.5.14.1 | Feb 6, 2018 | Feb 6, 2018 |
| Ubuntu | — | Upgrade libjackson-json-java | Feb 19, 2021 | Oct 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub