Vulnerabilities (CVE)

Vendor filter

Fasterxml Subscribe

Filter

19 total CVE
CVE Vendors Products Updated CVSS
CVE-2019-12814 2 Fasterxml, Debian 2 Jackson-databind, Debian Linux 2019-06-23 4.3
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar...
CVE-2019-12086 2 Fasterxml, Debian 2 Jackson-databind, Debian Linux 2019-05-30 5.0
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the...
CVE-2018-19362 3 Fasterxml, Debian, Oracle 7 Jackson-databind, Debian Linux, Business Process Management Suite and 4 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
CVE-2018-19361 3 Fasterxml, Debian, Oracle 7 Jackson-databind, Debian Linux, Business Process Management Suite and 4 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
CVE-2018-19360 3 Fasterxml, Debian, Oracle 7 Jackson-databind, Debian Linux, Business Process Management Suite and 4 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
CVE-2018-14721 3 Fasterxml, Debian, Oracle 11 Jackson-databind, Debian Linux, Banking Platform and 8 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CVE-2018-14720 3 Fasterxml, Debian, Oracle 11 Jackson-databind, Debian Linux, Banking Platform and 8 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CVE-2018-14719 3 Fasterxml, Debian, Oracle 10 Jackson-databind, Debian Linux, Banking Platform and 7 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
CVE-2018-14718 3 Fasterxml, Debian, Oracle 10 Jackson-databind, Debian Linux, Banking Platform and 7 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
CVE-2018-12023 3 Fasterxml, Oracle, Fedoraproject 19 Jackson-databind, Banking Platform, Communications Billing And Revenue Management and 16 more 2019-05-30 5.1
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can...
CVE-2018-12022 3 Fasterxml, Fedoraproject, Oracle 4 Jackson-databind, Fedora, Jd Edwards Enterpriseone Tools and 1 more 2019-05-30 5.1
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework)...
CVE-2018-7489 3 Fasterxml, Debian, Oracle 4 Jackson-databind, Debian Linux, Communications Billing And Revenue Management and 1 more 2019-05-10 7.5
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending...
CVE-2017-7525 2 Fasterxml, Debian 3 Jackson-databind, Debian Linux, Jackson 2019-04-30 7.5
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the...
CVE-2018-1000873 2 Fasterxml, Redhat 2 Jackson-databind, Jboss Enterprise Application Platform 2019-04-16 4.3
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes...
CVE-2017-15095 2 Fasterxml, Debian 3 Jackson-databind, Debian Linux, Jackson 2019-01-16 7.5
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the...
CVE-2017-17485 2 Fasterxml, Debian 3 Jackson-databind, Jackson, Debian Linux 2018-10-17 7.5
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input...
CVE-2018-5968 1 Fasterxml 1 Jackson-databind 2018-09-27 5.1
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different...
CVE-2016-7051 1 Fasterxml 1 Jackson 2017-09-26 5.0
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
CVE-2016-3720 2 Fasterxml, Fedoraproject 2 Jackson, Fedora 2017-02-19 7.5
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.