First published: Thu Jan 09 2020(Updated: )
A flaw was found in FasterXML Jackson Databind which did not have entity expansion secured properly making it vulnerable to XML external entity (XXE). This vulnerability is similar to <a href="https://access.redhat.com/security/cve/CVE-2019-10172">CVE-2019-10172</a>. The primary threat from this flaw is data integrity.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el6ea | 0:2.9.0-6.redhat_00016.1.el6ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el6ea | 0:1.2.0-1.redhat_00007.1.el6ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el6ea | 0:1.1.0-1.redhat_00007.1.el6ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el6ea | 0:3.2.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el6ea | 0:6.0.21-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el6ea | 0:1.6.0-1.redhat_00006.1.el6ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el6ea | 0:2.10.4-3.redhat_00002.1.el6ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el6ea | 0:1.9.3-1.redhat_00002.1.el6ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el6ea | 0:2.0.10-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el6ea | 0:5.0.19-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el6ea | 0:1.7.2-3.Final_redhat_00004.1.el6ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el6ea | 0:3.7.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el6ea | 0:2.0.32-1.SP1_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el6ea | 0:7.3.4-3.GA_redhat_00003.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el6ea | 0:1.10.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el6ea | 0:1.0.12-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el7ea | 0:2.9.0-6.redhat_00016.1.el7ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el7ea | 0:1.2.0-1.redhat_00007.1.el7ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el7ea | 0:1.1.0-1.redhat_00007.1.el7ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el7ea | 0:3.2.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el7ea | 0:6.0.21-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el7ea | 0:1.6.0-1.redhat_00006.1.el7ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el7ea | 0:2.10.4-3.redhat_00002.1.el7ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el7ea | 0:1.9.3-1.redhat_00002.1.el7ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el7ea | 0:2.0.10-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el7ea | 0:5.0.19-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el7ea | 0:1.7.2-3.Final_redhat_00004.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el7ea | 0:3.7.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el7ea | 0:2.0.32-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el7ea | 0:7.3.4-3.GA_redhat_00003.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el7ea | 0:1.10.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el7ea | 0:1.0.12-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el8ea | 0:2.9.0-6.redhat_00016.1.el8ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el8ea | 0:1.2.0-1.redhat_00007.1.el8ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el8ea | 0:1.1.0-1.redhat_00007.1.el8ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el8ea | 0:3.2.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el8ea | 0:6.0.21-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el8ea | 0:1.6.0-1.redhat_00006.1.el8ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el8ea | 0:2.10.4-3.redhat_00002.1.el8ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el8ea | 0:1.9.3-1.redhat_00002.1.el8ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el8ea | 0:2.0.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el8ea | 0:5.0.19-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el8ea | 0:1.7.2-3.Final_redhat_00004.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el8ea | 0:3.7.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el8ea | 0:2.0.32-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el8ea | 0:7.3.4-3.GA_redhat_00003.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el8ea | 0:1.10.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el8ea | 0:1.0.12-1.Final_redhat_00001.1.el8ea |
redhat/rh-maven35-jackson-databind | <0:2.7.6-2.12.el7 | 0:2.7.6-2.12.el7 |
redhat/ovirt-engine-dwh | <0:4.4.4.2-1.el8e | 0:4.4.4.2-1.el8e |
redhat/ovirt-web-ui | <0:1.6.6-1.el8e | 0:1.6.6-1.el8e |
redhat/rhv-log-collector-analyzer | <0:1.0.6-1.el8e | 0:1.0.6-1.el8e |
redhat/vdsm-jsonrpc-java | <0:1.6.0-1.el8e | 0:1.6.0-1.el8e |
redhat/jackson-databind | <2.11.0 | 2.11.0 |
redhat/jackson-databind | <2.10.5.1 | 2.10.5.1 |
Atlassian Confluence Data Center | =8 | |
Atlassian Confluence Server | =8 | |
Atlassian Jira Software Data Center | =8.20.0 | |
Atlassian Jira Software Data Center | =9.4.0 | |
Atlassian Jira Software Data Center | =9.5.0 | |
Atlassian Jira Software Data Center | =9.6.0 | |
VMware Aria Automation | =8.16 | |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.6.0<=2.6.7.3 | 2.6.7.4 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.10.0.0<=2.10.5.0 | 2.10.5.1 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.7.0.0<=2.9.10.6 | 2.9.10.7 |
FasterXML jackson-databind | >=2.6.0<2.6.7.4 | |
FasterXML jackson-databind | >=2.9.0<2.9.10.7 | |
FasterXML jackson-databind | >=2.10.0<2.10.5.1 | |
NetApp OnCommand API Services | ||
NetApp OnCommand Workflow Automation | ||
NetApp Service Level Manager | ||
Fedoraproject Fedora | =32 | |
Quarkus Quarkus | <=1.6.1 | |
Apache IoTDB | <0.12.0 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Agile Product Lifecycle Management Integration Pack E-business Suite | =3.6 | |
Oracle Banking Apis | >=18.1<=18.3 | |
Oracle Banking Apis | =19.1 | |
Oracle Banking Apis | =19.2 | |
Oracle Banking Apis | =20.1 | |
Oracle Banking Apis | =21.1 | |
Oracle Banking Platform | =2.6.2 | |
Oracle Banking Platform | =2.7.0 | |
Oracle Banking Platform | =2.7.1 | |
Oracle Banking Platform | =2.8.0 | |
Oracle Banking Platform | =2.9.0 | |
Oracle Banking Platform | =2.10.0 | |
Oracle Banking Treasury Management | =4.4 | |
Oracle Blockchain Platform | <21.1.2 | |
Oracle Coherence | =12.2.1.4.0 | |
Oracle Coherence | =14.1.1.0.0 | |
Oracle Commerce Platform | >=11.3.0<=11.3.2 | |
Oracle Commerce Platform | =11.2.0 | |
Oracle Communications Billing and Revenue Management | =7.5.0.23.0 | |
Oracle Communications Billing and Revenue Management | =12.0.0.3.0 | |
Oracle Communications Cloud Native Core Unified Data Repository | =1.4.0 | |
Oracle Communications Convergent Charging Controller | =12.0.4.0.0 | |
Oracle Communications Evolved Communications Application Server | =7.1 | |
Oracle Communications Instant Messaging Server | =10.0.1.5.0 | |
Oracle Communications Interactive Session Recorder | =6.3 | |
Oracle Communications Interactive Session Recorder | =6.4 | |
Oracle Communications Network Charging And Control | =12.0.4.0.0 | |
Oracle Communications Offline Mediation Controller | =12.0.0.3 | |
Oracle Communications Pricing Design Center | =12.0.0.4.0 | |
Oracle Communications Services Gatekeeper | =7.0 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle Goldengate Application Adapters | =19.1.0.0.0 | |
Oracle Health Sciences Empirica Signal | =9.0 | |
Oracle Health Sciences Empirica Signal | =9.1 | |
Oracle Insurance Policy Administration | >=11.1.0<=11.3.0 | |
Oracle Insurance Policy Administration | =11.0.2 | |
Oracle Insurance Rules Palette | >=11.1.0<=11.3.0 | |
Oracle Insurance Rules Palette | =11.0.2 | |
Oracle Jd Edwards Enterpriseone Orchestrator | <9.2.5.3 | |
Oracle Jd Edwards Enterpriseone Tools | <9.2.5.3 | |
Oracle Primavera Gateway | >=17.7<=17.12 | |
Oracle Primavera Gateway | >=17.12.0<=17.12.11 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.11 | |
Oracle Primavera Gateway | >=19.12.0<=19.12.10 | |
Oracle Primavera Gateway | =20.12.0 | |
Oracle Retail Service Backbone | =14.1.3.2 | |
Oracle Retail Service Backbone | =15.0.3.1 | |
Oracle Retail Service Backbone | =16.0.3 | |
Oracle Retail Xstore Point of Service | =16.0.6 | |
Oracle Retail Xstore Point of Service | =17.0.4 | |
Oracle Retail Xstore Point of Service | =18.0.3 | |
Oracle Retail Xstore Point of Service | =19.0.2 | |
Oracle Retail Xstore Point of Service | =20.0.1 | |
Oracle SD-WAN Edge | =9.0 | |
Oracle Utilities Framework | =4.3.0.5.0 | |
Oracle Utilities Framework | =4.3.0.6.0 | |
Oracle Utilities Framework | =4.4.0.0.0 | |
Oracle Utilities Framework | =4.4.0.2.0 | |
Oracle Utilities Framework | =4.4.0.3.0 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
Oracle Communications Messaging Server | =8.0.2 | |
Oracle Communications Messaging Server | =8.1 | |
IBM IBM® Db2® on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | <=v3.5 through refresh 10v4.0 through refresh 9v4.5 through refresh 3v4.6 through refresh 6v4.7 through refresh 4v4.8 through refresh 4 |
There is currently no known mitigation for this flaw.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)