First published: Wed Dec 23 2020(Updated: )
A flaw was found in jackson-databind. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.fasterxml.jackson.core:jackson-databind | <2.6.7.5 | 2.6.7.5 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.7.0<2.9.10.8 | 2.9.10.8 |
redhat/jackson-databind | <2.9.10.8 | 2.9.10.8 |
FasterXML jackson-databind | >=2.0.0<2.6.7.5 | |
FasterXML jackson-databind | >=2.7.0<2.9.10.8 | |
Netapp Cloud Backup | ||
NetApp Service Level Manager | ||
Debian Debian Linux | =9.0 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Application Testing Suite | =13.3.0.1 | |
Oracle Autovue For Agile Product Lifecycle Management | =21.0.2 | |
Oracle Banking Platform | =2.6.2 | |
Oracle Banking Platform | =2.7.0 | |
Oracle Banking Platform | =2.7.1 | |
Oracle Banking Platform | =2.8.0 | |
Oracle Banking Platform | =2.9.0 | |
Oracle Banking Platform | =2.10.0 | |
Oracle Banking Treasury Management | =14.4 | |
Oracle Banking Virtual Account Management | =14.2.0 | |
Oracle Banking Virtual Account Management | =14.3.0 | |
Oracle Banking Virtual Account Management | =14.5.0 | |
Oracle Blockchain Platform | <=21.1.2 | |
Oracle Commerce Platform | >=11.3.0<=11.3.2 | |
Oracle Commerce Platform | =11.2.0 | |
Oracle Communications Billing and Revenue Management | =7.5.0.23.0 | |
Oracle Communications Billing and Revenue Management | =12.0.0.3.0 | |
Oracle Communications Cloud Native Core Policy | =1.14.0 | |
Oracle Communications Cloud Native Core Unified Data Repository | =1.4.0 | |
Oracle Communications Convergent Charging Controller | =12.0.4.0.0 | |
Oracle Communications Diameter Signaling Router | >=8.0.0<=8.5.0 | |
Oracle Communications Evolved Communications Application Server | =7.1 | |
Oracle Communications Instant Messaging Server | =10.0.1.5.0 | |
Oracle Communications Interactive Session Recorder | =6.3 | |
Oracle Communications Interactive Session Recorder | =6.4 | |
Oracle Communications Messaging Server | =8.0.2 | |
Oracle Communications Messaging Server | =8.1 | |
Oracle Communications Network Charging And Control | =12.0.4.0.0 | |
Oracle Communications Offline Mediation Controller | =12.0.0.3 | |
Oracle Communications Pricing Design Center | =12.0.0.4.0 | |
Oracle Communications Services Gatekeeper | =7.0 | |
Oracle Communications Session Route Manager | >=8.2.0.0<=8.2.2.1 | |
Oracle Communications Unified Inventory Management | =7.4.1 | |
Oracle Documaker | =12.6.3 | |
Oracle Documaker | =12.6.4 | |
Oracle Goldengate Application Adapters | =19.1.0.0.0 | |
Oracle Insurance Policy Administration | >=11.1.0<=11.3.0 | |
Oracle Insurance Policy Administration | =11.0.2 | |
Oracle Insurance Rules Palette | >=11.1.0<=11.3.0 | |
Oracle Insurance Rules Palette | =11.0.2 | |
Oracle Jd Edwards Enterpriseone Orchestrator | <9.2.5.3 | |
Oracle Jd Edwards Enterpriseone Tools | <=9.2.5.3 | |
Oracle Primavera Gateway | >=17.12.0<=17.12.11 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.11 | |
Oracle Primavera Gateway | >=19.12.0<=19.12.10 | |
Oracle Primavera Gateway | =20.12.0 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Primavera Unifier | =20.12 | |
Oracle Retail Customer Management and Segmentation Foundation | >=16.0<=19.0 | |
Oracle Retail Merchandising System | =15.0.3 | |
Oracle Retail Service Backbone | =14.1.3.2 | |
Oracle Retail Service Backbone | =15.0.3.1 | |
Oracle Retail Service Backbone | =16.0.3 | |
Oracle Retail Xstore Point of Service | =16.0.6 | |
Oracle Retail Xstore Point of Service | =17.0.4 | |
Oracle Retail Xstore Point of Service | =18.0.3 | |
Oracle Retail Xstore Point of Service | =19.0.2 | |
Oracle WebCenter Portal | =12.2.1.3.0 | |
Oracle WebCenter Portal | =12.2.1.4.0 | |
IBM IBM® Db2® on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | <=v3.5 through refresh 10v4.0 through refresh 9v4.5 through refresh 3v4.6 through refresh 6v4.7 through refresh 4v4.8 through refresh 4 |
The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` * avoid: oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS, org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS, org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS, org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS, org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool, org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource, org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource, org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource, org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource, com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource, com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource in the classpath
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.