First published: Wed Mar 18 2020(Updated: )
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.4. FasterXML jackson-databind 2.x mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el6ea | 0:2.1.3-1.redhat_00001.1.el6ea |
redhat/eap7-elytron-web | <0:1.2.5-1.Final_redhat_00001.1.el6ea | 0:1.2.5-1.Final_redhat_00001.1.el6ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-13.SP3_redhat_00011.1.el6ea | 0:2.3.5-13.SP3_redhat_00011.1.el6ea |
redhat/eap7-hal-console | <0:3.0.23-1.Final_redhat_00001.1.el6ea | 0:3.0.23-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el6ea | 0:5.3.17-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el6ea | 0:6.0.20-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el6ea | 0:1.4.22-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-databind | <0:2.9.10.4-1.redhat_00001.1.el6ea | 0:2.9.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el6ea | 0:2.0.6-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el6ea | 0:2.1.15-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-modules | <0:1.8.10-1.Final_redhat_00001.1.el6ea | 0:1.8.10-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.3.1-13.Final_redhat_00014.1.el6ea | 0:1.3.1-13.Final_redhat_00014.1.el6ea |
redhat/eap7-jboss-xnio-base | <0:3.7.6-4.SP3_redhat_00001.1.el6ea | 0:3.7.6-4.SP3_redhat_00001.1.el6ea |
redhat/eap7-resteasy | <0:3.6.1-10.SP9_redhat_00001.1.el6ea | 0:3.6.1-10.SP9_redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el6ea | 0:2.0.30-4.SP4_redhat_00001.1.el6ea |
redhat/eap7-weld-core | <0:3.0.6-4.Final_redhat_00004.1.el6ea | 0:3.0.6-4.Final_redhat_00004.1.el6ea |
redhat/eap7-wildfly | <0:7.2.9-4.GA_redhat_00003.1.el6ea | 0:7.2.9-4.GA_redhat_00003.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.6.8-1.Final_redhat_00001.1.el6ea | 0:1.6.8-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el6ea | 0:1.0.22-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.11-1.Final_redhat_00001.1.el6ea | 0:1.1.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el7ea | 0:2.1.3-1.redhat_00001.1.el7ea |
redhat/eap7-elytron-web | <0:1.2.5-1.Final_redhat_00001.1.el7ea | 0:1.2.5-1.Final_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-13.SP3_redhat_00011.1.el7ea | 0:2.3.5-13.SP3_redhat_00011.1.el7ea |
redhat/eap7-hal-console | <0:3.0.23-1.Final_redhat_00001.1.el7ea | 0:3.0.23-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el7ea | 0:5.3.17-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el7ea | 0:6.0.20-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el7ea | 0:1.4.22-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <0:2.9.10.4-1.redhat_00001.1.el7ea | 0:2.9.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el7ea | 0:2.0.6-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el7ea | 0:2.1.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-modules | <0:1.8.10-1.Final_redhat_00001.1.el7ea | 0:1.8.10-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.3.1-13.Final_redhat_00014.1.el7ea | 0:1.3.1-13.Final_redhat_00014.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.6-4.SP3_redhat_00001.1.el7ea | 0:3.7.6-4.SP3_redhat_00001.1.el7ea |
redhat/eap7-resteasy | <0:3.6.1-10.SP9_redhat_00001.1.el7ea | 0:3.6.1-10.SP9_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el7ea | 0:2.0.30-4.SP4_redhat_00001.1.el7ea |
redhat/eap7-weld-core | <0:3.0.6-4.Final_redhat_00004.1.el7ea | 0:3.0.6-4.Final_redhat_00004.1.el7ea |
redhat/eap7-wildfly | <0:7.2.9-4.GA_redhat_00003.1.el7ea | 0:7.2.9-4.GA_redhat_00003.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.6.8-1.Final_redhat_00001.1.el7ea | 0:1.6.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el7ea | 0:1.0.22-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.11-1.Final_redhat_00001.1.el7ea | 0:1.1.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-dom4j | <0:2.1.3-1.redhat_00001.1.el8ea | 0:2.1.3-1.redhat_00001.1.el8ea |
redhat/eap7-elytron-web | <0:1.2.5-1.Final_redhat_00001.1.el8ea | 0:1.2.5-1.Final_redhat_00001.1.el8ea |
redhat/eap7-glassfish-jsf | <0:2.3.5-13.SP3_redhat_00011.1.el8ea | 0:2.3.5-13.SP3_redhat_00011.1.el8ea |
redhat/eap7-hal-console | <0:3.0.23-1.Final_redhat_00001.1.el8ea | 0:3.0.23-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate | <0:5.3.17-1.Final_redhat_00001.1.el8ea | 0:5.3.17-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-validator | <0:6.0.20-1.Final_redhat_00001.1.el8ea | 0:6.0.20-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar | <0:1.4.22-1.Final_redhat_00001.1.el8ea | 0:1.4.22-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-databind | <0:2.9.10.4-1.redhat_00001.1.el8ea | 0:2.9.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jboss-genericjms | <0:2.0.6-1.Final_redhat_00001.1.el8ea | 0:2.0.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-logmanager | <0:2.1.15-1.Final_redhat_00001.1.el8ea | 0:2.1.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-modules | <0:1.8.10-1.Final_redhat_00001.1.el8ea | 0:1.8.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.3.1-13.Final_redhat_00014.1.el8ea | 0:1.3.1-13.Final_redhat_00014.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.6-4.SP3_redhat_00001.1.el8ea | 0:3.7.6-4.SP3_redhat_00001.1.el8ea |
redhat/eap7-resteasy | <0:3.6.1-10.SP9_redhat_00001.1.el8ea | 0:3.6.1-10.SP9_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.30-4.SP4_redhat_00001.1.el8ea | 0:2.0.30-4.SP4_redhat_00001.1.el8ea |
redhat/eap7-weld-core | <0:3.0.6-4.Final_redhat_00004.1.el8ea | 0:3.0.6-4.Final_redhat_00004.1.el8ea |
redhat/eap7-wildfly | <0:7.2.9-4.GA_redhat_00003.1.el8ea | 0:7.2.9-4.GA_redhat_00003.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.6.8-1.Final_redhat_00001.1.el8ea | 0:1.6.8-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <0:1.0.22-1.Final_redhat_00001.1.el8ea | 0:1.0.22-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-transaction-client | <0:1.1.11-1.Final_redhat_00001.1.el8ea | 0:1.1.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el6ea | 0:1.6.2-1.Final_redhat_00001.1.el6ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el6ea | 0:2.3.9-11.SP11_redhat_00001.1.el6ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el6ea | 0:3.2.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el6ea | 0:9.4.19-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el6ea | 0:2.10.4-1.redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el6ea | 0:1.7.1-7.Final_redhat_00009.1.el6ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el6ea | 0:3.7.8-1.SP1_redhat_00001.1.el6ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el6ea | 0:4.1.48-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el6ea | 0:7.3.2-4.GA_redhat_00002.1.el6ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el6ea | 0:1.5.2-1.Final_redhat_00002.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el6ea | 0:1.10.7-1.Final_redhat_00001.1.el6ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el7ea | 0:1.6.2-1.Final_redhat_00001.1.el7ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el7ea | 0:2.3.9-11.SP11_redhat_00001.1.el7ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el7ea | 0:3.2.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el7ea | 0:9.4.19-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el7ea | 0:2.10.4-1.redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el7ea | 0:1.7.1-7.Final_redhat_00009.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el7ea | 0:3.7.8-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el7ea | 0:4.1.48-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el7ea | 0:7.3.2-4.GA_redhat_00002.1.el7ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el7ea | 0:1.5.2-1.Final_redhat_00002.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el7ea | 0:1.10.7-1.Final_redhat_00001.1.el7ea |
redhat/eap7-elytron-web | <0:1.6.2-1.Final_redhat_00001.1.el8ea | 0:1.6.2-1.Final_redhat_00001.1.el8ea |
redhat/eap7-glassfish-jsf | <0:2.3.9-11.SP11_redhat_00001.1.el8ea | 0:2.3.9-11.SP11_redhat_00001.1.el8ea |
redhat/eap7-hal-console | <0:3.2.9-1.Final_redhat_00001.1.el8ea | 0:3.2.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan | <0:9.4.19-1.Final_redhat_00001.1.el8ea | 0:9.4.19-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00001.1.el8ea | 0:2.10.4-1.redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.1-7.Final_redhat_00009.1.el8ea | 0:1.7.1-7.Final_redhat_00009.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.8-1.SP1_redhat_00001.1.el8ea | 0:3.7.8-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-netty | <0:4.1.48-1.Final_redhat_00001.1.el8ea | 0:4.1.48-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.2-4.GA_redhat_00002.1.el8ea | 0:7.3.2-4.GA_redhat_00002.1.el8ea |
redhat/eap7-wildfly-common | <0:1.5.2-1.Final_redhat_00002.1.el8ea | 0:1.5.2-1.Final_redhat_00002.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.7-1.Final_redhat_00001.1.el8ea | 0:1.10.7-1.Final_redhat_00001.1.el8ea |
FasterXML jackson-databind | >=2.0.0<2.6.7.4 | |
FasterXML jackson-databind | >=2.9.0<2.9.10.4 | |
Debian Debian Linux | =8.0 | |
Netapp Steelstore Cloud Integrated Storage | ||
Oracle Agile PLM | =9.3.6 | |
Oracle Autovue For Agile Product Lifecycle Management | =21.0.2 | |
Oracle Banking Digital Experience | =18.1 | |
Oracle Banking Digital Experience | =18.2 | |
Oracle Banking Digital Experience | =18.3 | |
Oracle Banking Digital Experience | =19.1 | |
Oracle Banking Digital Experience | =19.2 | |
Oracle Banking Digital Experience | =20.1 | |
Oracle Banking Platform | >=2.4.0<=2.9.0 | |
Oracle Communications Calendar Server | =8.0.0.4.0 | |
Oracle Communications Contacts Server | =8.0.0.4.0 | |
Oracle Communications Contacts Server | =8.0.0.5.0 | |
Oracle Communications Diameter Signaling Router | >=8.0.0<=8.2.2 | |
Oracle Communications Element Manager | >=8.2.0<=8.2.2 | |
Oracle Communications Evolved Communications Application Server | =7.1 | |
Oracle Communications Instant Messaging Server | =10.0.1.4.0 | |
Oracle Communications Network Charging And Control | >=12.0.0<=12.0.3 | |
Oracle Communications Network Charging And Control | =6.0.1 | |
Oracle Communications Session Report Manager | >=8.2.0<=8.2.2 | |
Oracle Communications Session Route Manager | >=8.2.0<=8.2.2 | |
Oracle Enterprise Manager Base Platform | =13.3.0.0 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6<=8.1.0 | |
Oracle Financial Services Institutional Performance Analytics | =8.0.6 | |
Oracle Financial Services Institutional Performance Analytics | =8.0.7 | |
Oracle Financial Services Institutional Performance Analytics | =8.1.0 | |
Oracle Financial Services Price Creation and Discovery | =8.0.6 | |
Oracle Financial Services Price Creation and Discovery | =8.0.7 | |
Oracle Financial Services Retail Customer Analytics | =8.0.6 | |
Oracle Global Lifecycle Management Opatch | <12.2.0.1.20 | |
Oracle Insurance Policy Administration J2EE | =11.0.2.25 | |
Oracle Insurance Policy Administration J2EE | =11.1.0.15 | |
Oracle Jd Edwards Enterpriseone Orchestrator | <9.2.4.2 | |
Oracle Jd Edwards Enterpriseone Tools | <9.2.4.2 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =16.1 | |
Oracle Primavera Unifier | =16.2 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Retail Merchandising System | =15.0 | |
Oracle Retail Sales Audit | =14.1 | |
Oracle Retail Service Backbone | =14.1 | |
Oracle Retail Service Backbone | =15.0 | |
Oracle Retail Service Backbone | =16.0 | |
Oracle Retail Xstore Point of Service | =15.0 | |
Oracle Retail Xstore Point of Service | =16.0 | |
Oracle Retail Xstore Point of Service | =17.0 | |
Oracle Retail Xstore Point of Service | =18.0 | |
Oracle Retail Xstore Point of Service | =19.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
redhat/Jackson-databind | <2.9.10.4 | 2.9.10.4 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.0.0<2.6.7.4 | 2.6.7.4 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.7.0<2.9.10.4 | 2.9.10.4 |
IBM RQM | <=6.0.6.1 | |
IBM RQM | <=6.0.6 | |
IBM ETM | <=7.0.0 | |
IBM RQM | <=6.0.2 | |
IBM EWM | <=7.0 | |
IBM CLM | <=6.0.6.1 | |
IBM CLM | <=6.0.6 | |
IBM ELM | <=7.0 | |
IBM CLM | <=6.0.2 | |
IBM RDNG | <=6.0.2 | |
IBM RDNG | <=6.0.6.1 | |
IBM RDNG | <=6.0.6 | |
IBM DOORS Next | <=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)