CVE |
Vendors |
Products |
Updated |
CVSS |
CVE-2019-16943 |
2 Fasterxml, Debian |
2 Jackson-databind, Debian Linux |
2019-10-12 |
7.5 |
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy... |
CVE-2019-17267 |
1 Fasterxml |
1 Jackson-databind |
2019-10-10 |
7.5 |
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup. |
CVE-2016-7051 |
1 Fasterxml |
2 Jackson, Jackson-dataformat-xml |
2019-10-10 |
5.0 |
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD. |
CVE-2016-3720 |
2 Fasterxml, Fedoraproject |
3 Jackson, Fedora, Jackson-dataformat-xml |
2019-10-10 |
7.5 |
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors. |
CVE-2019-16942 |
2 Fasterxml, Debian |
2 Jackson-databind, Debian Linux |
2019-10-08 |
7.5 |
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp... |
CVE-2019-14379 |
3 Fasterxml, Netapp, Debian |
4 Jackson-databind, Oncommand Workflow Automation, Snapcenter and 1 more |
2019-10-06 |
7.5 |
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution. |
CVE-2018-7489 |
4 Fasterxml, Debian, Oracle and 1 more |
5 Jackson-databind, Debian Linux, Communications Billing And Revenue Management and 2 more |
2019-09-27 |
7.5 |
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending... |
CVE-2018-5968 |
3 Fasterxml, Redhat, Debian |
4 Jackson-databind, Virtualization, Virtualization Host and 1 more |
2019-09-27 |
5.1 |
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different... |
CVE-2018-14721 |
4 Fasterxml, Debian, Oracle and 1 more |
14 Jackson-databind, Debian Linux, Banking Platform and 11 more |
2019-09-27 |
7.5 |
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization. |
CVE-2018-14720 |
4 Fasterxml, Debian, Oracle and 1 more |
13 Jackson-databind, Debian Linux, Banking Platform and 10 more |
2019-09-27 |
7.5 |
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. |
CVE-2017-7525 |
3 Fasterxml, Debian, Redhat |
6 Jackson-databind, Debian Linux, Jackson and 3 more |
2019-09-27 |
7.5 |
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the... |
CVE-2017-17485 |
3 Fasterxml, Debian, Redhat |
7 Jackson-databind, Jackson, Debian Linux and 4 more |
2019-09-27 |
7.5 |
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input... |
CVE-2017-15095 |
3 Fasterxml, Debian, Redhat |
4 Jackson-databind, Debian Linux, Jackson and 1 more |
2019-09-27 |
7.5 |
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the... |
CVE-2019-16335 |
1 Fasterxml |
1 Jackson-databind |
2019-09-24 |
7.5 |
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. |
CVE-2019-14540 |
1 Fasterxml |
1 Jackson-databind |
2019-09-24 |
7.5 |
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. |
CVE-2019-12086 |
2 Fasterxml, Debian |
2 Jackson-databind, Debian Linux |
2019-09-18 |
5.0 |
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the... |
CVE-2018-19362 |
4 Fasterxml, Debian, Oracle and 1 more |
12 Jackson-databind, Debian Linux, Business Process Management Suite and 9 more |
2019-09-17 |
7.5 |
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization. |
CVE-2018-19361 |
4 Fasterxml, Debian, Oracle and 1 more |
12 Jackson-databind, Debian Linux, Business Process Management Suite and 9 more |
2019-09-17 |
7.5 |
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization. |
CVE-2018-19360 |
4 Fasterxml, Debian, Oracle and 1 more |
12 Jackson-databind, Debian Linux, Business Process Management Suite and 9 more |
2019-09-17 |
7.5 |
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization. |
CVE-2018-14719 |
4 Fasterxml, Debian, Oracle and 1 more |
11 Jackson-databind, Debian Linux, Banking Platform and 8 more |
2019-09-17 |
7.5 |
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization. |