Vulnerabilities (CVE)

Vendor filter

Fasterxml Subscribe

Filter

25 total CVE
CVE Vendors Products Updated CVSS
CVE-2019-14540 1 Fasterxml 1 Jackson-databind 2019-09-18 7.5
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
CVE-2019-16335 1 Fasterxml 1 Jackson-databind 2019-09-18 7.5
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
CVE-2019-12086 2 Fasterxml, Debian 2 Jackson-databind, Debian Linux 2019-09-18 5.0
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the...
CVE-2018-19362 4 Fasterxml, Debian, Oracle and 1 more 12 Jackson-databind, Debian Linux, Business Process Management Suite and 9 more 2019-09-17 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
CVE-2018-19361 4 Fasterxml, Debian, Oracle and 1 more 12 Jackson-databind, Debian Linux, Business Process Management Suite and 9 more 2019-09-17 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
CVE-2018-19360 4 Fasterxml, Debian, Oracle and 1 more 12 Jackson-databind, Debian Linux, Business Process Management Suite and 9 more 2019-09-17 7.5
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
CVE-2018-14719 4 Fasterxml, Debian, Oracle and 1 more 11 Jackson-databind, Debian Linux, Banking Platform and 8 more 2019-09-17 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
CVE-2018-12023 5 Fasterxml, Oracle, Fedoraproject and 2 more 26 Jackson-databind, Banking Platform, Communications Billing And Revenue Management and 23 more 2019-09-17 5.1
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can...
CVE-2018-12022 5 Fasterxml, Fedoraproject, Oracle and 2 more 11 Jackson-databind, Fedora, Jd Edwards Enterpriseone Tools and 8 more 2019-09-17 5.1
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework)...
CVE-2017-15095 3 Fasterxml, Debian, Redhat 4 Jackson-databind, Debian Linux, Jackson and 1 more 2019-09-05 7.5
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the...
CVE-2019-14439 2 Fasterxml, Debian 2 Jackson-databind, Debian Linux 2019-09-05 5.0
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the...
CVE-2019-12814 2 Fasterxml, Debian 2 Jackson-databind, Debian Linux 2019-09-05 4.3
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar...
CVE-2019-12384 3 Fasterxml, Debian, Redhat 3 Jackson-databind, Debian Linux, Enterprise Linux 2019-09-05 4.3
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may...
CVE-2017-7525 3 Fasterxml, Debian, Redhat 6 Jackson-databind, Debian Linux, Jackson and 3 more 2019-08-30 7.5
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the...
CVE-2018-14721 4 Fasterxml, Debian, Oracle and 1 more 14 Jackson-databind, Debian Linux, Banking Platform and 11 more 2019-08-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CVE-2018-5968 3 Fasterxml, Redhat, Debian 4 Jackson-databind, Virtualization, Virtualization Host and 1 more 2019-08-29 5.1
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different...
CVE-2018-7489 4 Fasterxml, Debian, Oracle and 1 more 5 Jackson-databind, Debian Linux, Communications Billing And Revenue Management and 2 more 2019-08-22 7.5
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending...
CVE-2017-17485 3 Fasterxml, Debian, Redhat 7 Jackson-databind, Jackson, Debian Linux and 4 more 2019-08-22 7.5
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input...
CVE-2019-14379 3 Fasterxml, Netapp, Debian 4 Jackson-databind, Oncommand Workflow Automation, Snapcenter and 1 more 2019-08-22 7.5
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used, leading to remote code execution.
CVE-2018-14720 4 Fasterxml, Debian, Oracle and 1 more 13 Jackson-databind, Debian Linux, Banking Platform and 10 more 2019-08-21 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.