jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to serialize it cannot be achieved by an external attacker.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| Dell Powerstore Dsa2024225 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 29, 2024 |
| Dell Powerstore Dsa2024287 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jul 2, 2024 |
| Dell Powerstore Dsa2024336 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Aug 1, 2024 |
| Oracle Missing Cpu Oct 2023 | — | Apply the October 2023 Critical Patch Update (CPU) for Oracle Database | Oct 18, 2023 | Jun 14, 2023 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 35904051 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 35893811 for version 12.2.1.4.0. | Oct 19, 2023 | Jun 14, 2023 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Jun 14, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 14, 2023 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.0.10Upgrade Splunk Enterprise to version 9.2.2Upgrade Splunk Enterprise to version 9.1.5 | Sep 30, 2025 | Jun 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub