First published: Thu Jan 02 2020(Updated: )
A lacking of certain net.sf.ehcache blocking in FasterXML jackson-databind has an unknown impact and attack vector.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/candlepin | <0:2.6.16-1.el7 | 0:2.6.16-1.el7 |
redhat/foreman | <0:1.22.0.39-2.el7 | 0:1.22.0.39-2.el7 |
redhat/satellite | <0:6.6.3-1.el7 | 0:6.6.3-1.el7 |
redhat/tfm-rubygem-fog-ovirt | <0:1.2.3-1.el7 | 0:1.2.3-1.el7 |
redhat/tfm-rubygem-katello | <0:3.12.0.41-1.el7 | 0:3.12.0.41-1.el7 |
redhat/tfm-rubygem-runcible | <0:2.13.0-1.el7 | 0:2.13.0-1.el7 |
redhat/candlepin | <0:2.9.28-1.el7 | 0:2.9.28-1.el7 |
redhat/foreman | <0:1.24.1.24-1.el7 | 0:1.24.1.24-1.el7 |
redhat/foreman-installer | <1:1.24.1.21-1.el7 | 1:1.24.1.21-1.el7 |
redhat/pulp-rpm | <0:2.21.0.6-1.el7 | 0:2.21.0.6-1.el7 |
redhat/satellite | <0:6.7.2-1.el7 | 0:6.7.2-1.el7 |
redhat/tfm-rubygem-fog-vsphere | <0:3.2.1.1-1.el7 | 0:3.2.1.1-1.el7 |
redhat/tfm-rubygem-foreman-tasks | <0:0.17.5.6-1.el7 | 0:0.17.5.6-1.el7 |
redhat/tfm-rubygem-katello | <0:3.14.0.25-1.el7 | 0:3.14.0.25-1.el7 |
redhat/jackson-databind | <2.9.10.2 | 2.9.10.2 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.0.0<=2.6.7.3 | 2.6.7.4 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.9.0<=2.9.10.1 | 2.9.10.2 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.8.0<=2.8.11.4 | 2.8.11.5 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.7.0<=2.7.9.6 | 2.7.9.7 |
IBM RQM | <=6.0.6.1 | |
IBM RQM | <=6.0.6 | |
IBM ETM | <=7.0.0 | |
IBM RQM | <=6.0.2 | |
IBM EWM | <=7.0 | |
IBM CLM | <=6.0.6.1 | |
IBM CLM | <=6.0.6 | |
IBM ELM | <=7.0 | |
IBM CLM | <=6.0.2 | |
IBM RDNG | <=6.0.2 | |
IBM RDNG | <=6.0.6.1 | |
IBM RDNG | <=6.0.6 | |
IBM DOORS Next | <=7.0 | |
FasterXML jackson-databind | >=2.0.0<2.7.9.7 | |
FasterXML jackson-databind | >=2.8.0<2.8.11.5 | |
FasterXML jackson-databind | >=2.9.0<2.9.10.2 | |
oracle banking platform | >=2.4.0<=2.9.0 | |
Oracle Communications Billing and Revenue Management | =7.5.0.23.0 | |
Oracle Communications Billing and Revenue Management | =12.0.0.3.0 | |
Oracle Communications Cloud Native Core Network Slice Selection Function | =1.2.1 | |
Oracle Communications Contacts Server | =8.0.0.4.0 | |
oracle communications evolved communications application server | =7.1 | |
Oracle Communications Instant Messaging Server | =10.0.1.4.0 | |
oracle communications network charging and control | >=12.0.0<=12.0.3 | |
oracle communications network charging and control | =6.0.1 | |
Oracle Customer Management and Segmentation Foundation | =18.0 | |
Oracle Enterprise Manager Base Platform | =13.3.0.0 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
oracle global lifecycle management opatch | <11.2.0.3.23 | |
oracle global lifecycle management opatch | >=12.2.0.1.0<12.2.0.1.19 | |
oracle global lifecycle management opatch | >=13.9.4.0.0<13.9.4.2.1 | |
Oracle GoldenGate Application Adapters | =19.1.0.0.0 | |
Oracle GoldenGate Stream Analytics | <19.1.0.0.1 | |
Oracle JD Edwards EnterpriseOne Orchestrator | <9.2.4.2 | |
Oracle JD Edwards EnterpriseOne Tools | <9.2.4.2 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =16.1 | |
Oracle Primavera Unifier | =16.2 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Retail Merchandising System | =15.0.3 | |
Oracle Retail Merchandising System | =16.0.2 | |
Oracle Retail Merchandising System | =16.0.3 | |
Oracle Retail Sales Audit | =14.1 | |
Oracle Retail Xstore Office Cloud Service | =15.0 | |
Oracle Retail Xstore Office Cloud Service | =16.0 | |
Oracle Retail Xstore Office Cloud Service | =17.0 | |
Oracle Retail Xstore Office Cloud Service | =18.0 | |
Oracle Retail Xstore Office Cloud Service | =19.0 | |
Oracle Siebel Engineering - Installer & Deployment | <=2.20.5 | |
Oracle Siebel User Interface Framework | <=20.5 | |
Oracle Trace File Analyzer | =12.2.0.1 | |
Oracle Trace File Analyzer | =18c | |
Oracle Trace File Analyzer | =19c | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Debian GNU/Linux | =8.0 | |
NetApp Active IQ Unified Manager | >=7.3 | |
netapp active iq unified manager windows | >=7.3 | |
NetApp Active IQ Unified Manager for VMware vSphere | >=9.5 | |
NetApp OnCommand API Services | ||
NetApp Service Level Manager | ||
NetApp SnapCenter | ||
NetApp SteelStore | ||
Debian | =8.0 |
The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS`
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2019-20330 is considered to be unknown due to insufficient details about its impact and attack vector.
To fix CVE-2019-20330, update to the recommended versions of FasterXML jackson-databind as specified in the software's documentation.
CVE-2019-20330 affects various versions of FasterXML jackson-databind, including 2.x before 2.6.7.4, 2.7.x before 2.7.9.7, and so on.
Yes, you should upgrade to the specified fixed versions, such as jackson-databind 2.9.10.2 or others depending on your current version.
While the exact implications of CVE-2019-20330 are not well documented, it is advisable to apply patches to mitigate any risks associated with the vulnerability.