First published: Wed Jan 30 2019(Updated: )
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FasterXML jackson-databind | >=2.7.0<2.7.9.4 | |
FasterXML jackson-databind | >=2.8.0<2.8.11.2 | |
FasterXML jackson-databind | >=2.9.0<2.9.6 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =29 | |
Oracle Jd Edwards Enterpriseone Tools | =9.2 | |
Oracle Retail Merchandising System | =15.0 | |
Redhat Automation Manager | =7.3.1 | |
Redhat Decision Manager | =7.3.1 | |
Redhat Jboss Brms | =6.4.10 | |
Redhat Jboss Enterprise Application Platform | =7.2.0 | |
Redhat Openshift Container Platform | =3.11 | |
Redhat Single Sign-on | =7.3 | |
debian/jackson-databind | 2.9.8-3+deb10u3 2.9.8-3+deb10u5 2.12.1-1+deb11u1 2.14.0-1 | |
redhat/jackson-databind | <2.7.9.4 | 2.7.9.4 |
redhat/jackson-databind | <2.8.11.2 | 2.8.11.2 |
redhat/jackson-databind | <2.9.6 | 2.9.6 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.9.0<2.9.6 | 2.9.6 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.8.0<=2.8.11.1 | 2.8.11.2 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.7.0<=2.7.9.3 | 2.7.9.4 |
IBM CLM | <=6.0.6.1 | |
IBM CLM | <=6.0.6 | |
IBM CLM | <=6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-12023.
CVE-2018-12023 has a severity level of 8.1 (High).
CVE-2018-12023 affects multiple Oracle products and IBM Disconnected Log Collector.
The affected versions of jackson-databind are 2.7.9.4, 2.8.11.2, and 2.9.6.
Yes, there are remediation steps available for jackson-databind. Please refer to the official sources for specific remediation steps.