First published: Thu Jan 09 2020(Updated: )
A flaw was found in FasterXML Jackson Databind which did not have entity expansion secured properly making it vulnerable to XML external entity (XXE). This vulnerability is similar to <a href="https://access.redhat.com/security/cve/CVE-2019-10172">CVE-2019-10172</a>. The primary threat from this flaw is data integrity.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el6ea | 0:2.9.0-6.redhat_00016.1.el6ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el6ea | 0:1.2.0-1.redhat_00007.1.el6ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el6ea | 0:1.1.0-1.redhat_00007.1.el6ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el6ea | 0:3.2.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el6ea | 0:6.0.21-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el6ea | 0:1.6.0-1.redhat_00006.1.el6ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el6ea | 0:2.10.4-3.redhat_00002.1.el6ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el6ea | 0:1.9.3-1.redhat_00002.1.el6ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el6ea | 0:2.0.10-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el6ea | 0:5.0.19-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el6ea | 0:1.7.2-3.Final_redhat_00004.1.el6ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el6ea | 0:3.7.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el6ea | 0:2.0.32-1.SP1_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el6ea | 0:7.3.4-3.GA_redhat_00003.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el6ea | 0:1.10.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el6ea | 0:1.0.12-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el7ea | 0:2.9.0-6.redhat_00016.1.el7ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el7ea | 0:1.2.0-1.redhat_00007.1.el7ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el7ea | 0:1.1.0-1.redhat_00007.1.el7ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el7ea | 0:3.2.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el7ea | 0:6.0.21-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el7ea | 0:1.6.0-1.redhat_00006.1.el7ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el7ea | 0:2.10.4-3.redhat_00002.1.el7ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el7ea | 0:1.9.3-1.redhat_00002.1.el7ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el7ea | 0:2.0.10-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el7ea | 0:5.0.19-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el7ea | 0:1.7.2-3.Final_redhat_00004.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el7ea | 0:3.7.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el7ea | 0:2.0.32-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el7ea | 0:7.3.4-3.GA_redhat_00003.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el7ea | 0:1.10.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el7ea | 0:1.0.12-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-databind | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el8ea | 0:2.9.0-6.redhat_00016.1.el8ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el8ea | 0:1.2.0-1.redhat_00007.1.el8ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el8ea | 0:1.1.0-1.redhat_00007.1.el8ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el8ea | 0:3.2.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el8ea | 0:6.0.21-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el8ea | 0:1.6.0-1.redhat_00006.1.el8ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el8ea | 0:2.10.4-3.redhat_00002.1.el8ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el8ea | 0:1.9.3-1.redhat_00002.1.el8ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el8ea | 0:2.0.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el8ea | 0:5.0.19-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el8ea | 0:1.7.2-3.Final_redhat_00004.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el8ea | 0:3.7.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el8ea | 0:2.0.32-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el8ea | 0:7.3.4-3.GA_redhat_00003.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el8ea | 0:1.10.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el8ea | 0:1.0.12-1.Final_redhat_00001.1.el8ea |
redhat/rh-maven35-jackson-databind | <0:2.7.6-2.12.el7 | 0:2.7.6-2.12.el7 |
redhat/ovirt-engine-dwh | <0:4.4.4.2-1.el8e | 0:4.4.4.2-1.el8e |
redhat/ovirt-web-ui | <0:1.6.6-1.el8e | 0:1.6.6-1.el8e |
redhat/rhv-log-collector-analyzer | <0:1.0.6-1.el8e | 0:1.0.6-1.el8e |
redhat/vdsm-jsonrpc-java | <0:1.6.0-1.el8e | 0:1.6.0-1.el8e |
redhat/jackson-databind | <2.11.0 | 2.11.0 |
redhat/jackson-databind | <2.10.5.1 | 2.10.5.1 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.6.0<=2.6.7.3 | 2.6.7.4 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.10.0.0<=2.10.5.0 | 2.10.5.1 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.7.0.0<=2.9.10.6 | 2.9.10.7 |
Atlassian Confluence Server/Data Center | =8 | |
Atlassian Confluence Server and Data Server | =8 | |
Atlassian Jira Software Data Center | =8.20.0 | |
Atlassian Jira Software Data Center | =9.4.0 | |
Atlassian Jira Software Data Center | =9.5.0 | |
Atlassian Jira Software Data Center | =9.6.0 | |
VMware Aria Automation | =8.16 | |
FasterXML Jackson Databind | >=2.6.0<2.6.7.4 | |
FasterXML Jackson Databind | >=2.9.0<2.9.10.7 | |
FasterXML Jackson Databind | >=2.10.0<2.10.5.1 | |
NetApp OnCommand API Services | ||
NetApp OnCommand Workflow Automation | ||
NetApp Service Level Manager | ||
Red Hat Fedora | =32 | |
Red Hat Quarkus | <=1.6.1 | |
Apache IoTDB | <0.12.0 | |
Oracle Agile Product Lifecycle Management Framework | =9.3.6 | |
Oracle Agile Product Lifecycle Management Integration Pack for E-Business Suite | =3.6 | |
Oracle Banking APIs | >=18.1<=18.3 | |
Oracle Banking APIs | =19.1 | |
Oracle Banking APIs | =19.2 | |
Oracle Banking APIs | =20.1 | |
Oracle Banking APIs | =21.1 | |
Oracle Banking Platform | =2.6.2 | |
Oracle Banking Platform | =2.7.0 | |
Oracle Banking Platform | =2.7.1 | |
Oracle Banking Platform | =2.8.0 | |
Oracle Banking Platform | =2.9.0 | |
Oracle Banking Platform | =2.10.0 | |
Oracle Banking Treasury Management | =4.4 | |
Oracle Blockchain Platform | <21.1.2 | |
Oracle Coherence | =12.2.1.4.0 | |
Oracle Coherence | =14.1.1.0.0 | |
Oracle Commerce | >=11.3.0<=11.3.2 | |
Oracle Commerce | =11.2.0 | |
Oracle Communications Billing and Revenue Management | =7.5.0.23.0 | |
Oracle Communications Billing and Revenue Management | =12.0.0.3.0 | |
Oracle Communications Cloud Native Core Unified Data Repository | =1.4.0 | |
Oracle Communications Convergent Charging Controller | =12.0.4.0.0 | |
Oracle Communications Evolved Communications Application Server | =7.1 | |
Oracle Communications Instant Messaging Server | =10.0.1.5.0 | |
Oracle Communications Interactive Session Recorder | =6.3 | |
Oracle Communications Interactive Session Recorder | =6.4 | |
Oracle Communications Network Charging and Control | =12.0.4.0.0 | |
Oracle Communications Offline Mediation Controller | =12.0.0.3 | |
Oracle Communications Pricing Design Center | =12.0.0.4.0 | |
GNU Gatekeeper | =7.0 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle GoldenGate Application Adapters | =19.1.0.0.0 | |
Oracle Health Sciences Empirica Signal | =9.0 | |
Oracle Health Sciences Empirica Signal | =9.1 | |
Oracle Insurance Policy Administration | >=11.1.0<=11.3.0 | |
Oracle Insurance Policy Administration | =11.0.2 | |
Oracle Insurance Rules Palette | >=11.1.0<=11.3.0 | |
Oracle Insurance Rules Palette | =11.0.2 | |
Oracle JD Edwards EnterpriseOne Orchestrator | <9.2.5.3 | |
Oracle JD Edwards EnterpriseOne Tools | <9.2.5.3 | |
Oracle Primavera Gateway | >=17.7<=17.12 | |
Oracle Primavera Gateway | >=17.12.0<=17.12.11 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.11 | |
Oracle Primavera Gateway | >=19.12.0<=19.12.10 | |
Oracle Primavera Gateway | =20.12.0 | |
Oracle Retail Service Backbone | =14.1.3.2 | |
Oracle Retail Service Backbone | =15.0.3.1 | |
Oracle Retail Service Backbone | =16.0.3 | |
Oracle Retail Xstore Office Cloud Service | =16.0.6 | |
Oracle Retail Xstore Office Cloud Service | =17.0.4 | |
Oracle Retail Xstore Office Cloud Service | =18.0.3 | |
Oracle Retail Xstore Office Cloud Service | =19.0.2 | |
Oracle Retail Xstore Office Cloud Service | =20.0.1 | |
Oracle SD-WAN Edge | =9.0 | |
Oracle Utilities | =4.3.0.5.0 | |
Oracle Utilities | =4.3.0.6.0 | |
Oracle Utilities | =4.4.0.0.0 | |
Oracle Utilities | =4.4.0.2.0 | |
Oracle Utilities | =4.4.0.3.0 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
Sun iPlanet Messaging Server | =8.0.2 | |
Sun iPlanet Messaging Server | =8.1 |
There is currently no known mitigation for this flaw.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-25649 is rated as a medium severity vulnerability due to its potential for causing denial of service conditions and information disclosure.
To mitigate CVE-2020-25649, update to the fixed versions of the affected packages such as eap7-jackson-databind to 0:2.10.4-1.redhat_00002.1.el6ea or newer.
CVE-2020-25649 affects several Red Hat packages including eap7-jackson-databind, eap7-activemq-artemis, and others.
CVE-2020-25649 is an XML External Entity (XXE) vulnerability that can allow attackers to exploit improperly secured endpoints.
While specific workarounds may exist, the best practice is to upgrade affected software to eliminate the vulnerability completely.