An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jackson-databind | Mar 12, 2019 | Mar 12, 2019 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jun 8, 2018 |
| Red_hat Jboss_eap | — | — | Nov 14, 2019 | Mar 21, 2019 |
| Redhat Openshift | — | Upgrade logging | Oct 8, 2019 | Mar 21, 2019 |
| Suse | — | Upgrade jackson-databind | Feb 4, 2022 | Mar 21, 2019 |
| Ubuntu | — | Upgrade libjackson2-databind-java (Ubuntu Pro) | Mar 22, 2023 | Mar 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub