First published: Thu Aug 13 2020(Updated: )
A flaw was found in the Jackson Databind package. This cause of the issue is due to a Java StackOverflow exception and a denial of service via a significant depth of nested objects.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/jackson-databind | <=2.9.8-3+deb10u3 | 2.9.8-3+deb10u5 2.12.1-1+deb11u1 2.14.0-1 |
redhat/jackson-databind | <0:2.14.1-2.el9 | 0:2.14.1-2.el9 |
redhat/eap7-jackson-databind | <0:2.12.6.1-1.redhat_00003.1.el8ea | 0:2.12.6.1-1.redhat_00003.1.el8ea |
redhat/eap7-jackson-databind | <0:2.12.6.1-1.redhat_00003.1.el7ea | 0:2.12.6.1-1.redhat_00003.1.el7ea |
redhat/rh-sso7-keycloak | <0:15.0.8-1.redhat_00001.1.el7 | 0:15.0.8-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:15.0.8-1.redhat_00001.1.el8 | 0:15.0.8-1.redhat_00001.1.el8 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el7 | 0:18.0.3-1.redhat_00001.1.el7 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el8 | 0:18.0.3-1.redhat_00001.1.el8 |
redhat/rh-sso7 | <0:1-5.el9 | 0:1-5.el9 |
redhat/rh-sso7-javapackages-tools | <0:6.0.0-7.el9 | 0:6.0.0-7.el9 |
redhat/rh-sso7-keycloak | <0:18.0.3-1.redhat_00001.1.el9 | 0:18.0.3-1.redhat_00001.1.el9 |
maven/com.fasterxml.jackson.core:jackson-databind | <=2.12.6.0 | 2.12.6.1 |
maven/com.fasterxml.jackson.core:jackson-databind | >=2.13.0<=2.13.2.0 | 2.13.2.1 |
FasterXML jackson-databind | <2.12.6.1 | |
FasterXML jackson-databind | >=2.13.0<2.13.2.1 | |
Oracle Big Data Spatial And Graph | <23.1 | |
Oracle Coherence | =14.1.1.0.0 | |
Oracle Commerce Platform | =11.3.0 | |
Oracle Commerce Platform | =11.3.1 | |
Oracle Commerce Platform | =11.3.2 | |
Oracle Communications Billing and Revenue Management | >=12.0.0.4.0<=12.0.0.6.0 | |
Oracle Communications Cloud Native Core Binding Support Function | =22.1.3 | |
Oracle Communications Cloud Native Core Console | =1.9.0 | |
Oracle Communications Cloud Native Core Network Repository Function | =22.1.2 | |
Oracle Communications Cloud Native Core Network Repository Function | =22.2.0 | |
Oracle Communications Cloud Native Core Network Slice Selection Function | =22.1.0 | |
Oracle Communications Cloud Native Core Network Slice Selection Function | =22.1.1 | |
Oracle Communications Cloud Native Core Security Edge Protection Proxy | =22.1.1 | |
Oracle Communications Cloud Native Core Service Communication Proxy | =22.2.0 | |
Oracle Communications Cloud Native Core Unified Data Repository | =22.2.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.7<=8.1.0.0 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.1.1.0 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.1.2.0 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.1.2.1 | |
Oracle Financial Services Behavior Detection Platform | >=8.1.1.0<=8.1.2.1 | |
Oracle Financial Services Behavior Detection Platform | =8.0.7.0.0 | |
Oracle Financial Services Behavior Detection Platform | =8.0.8 | |
Oracle Financial Services Crime And Compliance Management Studio | =8.0.8.2.0 | |
Oracle Financial Services Crime And Compliance Management Studio | =8.0.8.3.0 | |
Oracle Financial Services Enterprise Case Management | >=8.1.1.0<=8.1.2.1 | |
Oracle Financial Services Enterprise Case Management | =8.0.7.1 | |
Oracle Financial Services Enterprise Case Management | =8.0.7.2 | |
Oracle Financial Services Enterprise Case Management | =8.0.8.0 | |
Oracle Financial Services Enterprise Case Management | =8.0.8.1 | |
Oracle Financial Services Trade-based Anti Money Laundering | =8.0.7 | |
Oracle Financial Services Trade-based Anti Money Laundering | =8.0.8 | |
Oracle Global Lifecycle Management NextGen OUI Framework | <13.9.4.2.2 | |
Oracle Global Lifecycle Management NextGen OUI Framework | =13.9.4.2.2 | |
Oracle Global Lifecycle Management Opatch | <12.2.0.1.30 | |
Oracle Graph Server And Client | <22.2.0 | |
Oracle Health Sciences Empirica Signal | =9.1.0.5.2 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.59 | |
Oracle Primavera Gateway | >=17.12.0<=17.12.11 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.14 | |
Oracle Primavera Gateway | >=19.12.0<=19.12.13 | |
Oracle Primavera Gateway | >=20.12.0<=20.12.18 | |
Oracle Primavera Gateway | >=21.12.0<=21.12.1 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=17.12.0.0<=17.12.20.4 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=18.8.0.0<=18.8.25.4 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=19.12.0<=19.12.19.0 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=20.12.0.0<=21.12.4.0 | |
Oracle Primavera Unifier | >=17.0<=17.12 | |
Oracle Primavera Unifier | =18.0 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Primavera Unifier | =20.12 | |
Oracle Primavera Unifier | =21.12 | |
Oracle Retail Sales Audit | =15.0.3.1 | |
Oracle SD-WAN Edge | =9.0 | |
Oracle SD-WAN Edge | =9.1 | |
Oracle Spatial Studio | <20.1.0 | |
Oracle Utilities Framework | =4.3.0.5.0 | |
Oracle Utilities Framework | =4.3.0.6.0 | |
Oracle Utilities Framework | =4.4.0.0.0 | |
Oracle Utilities Framework | =4.4.0.2.0 | |
Oracle Utilities Framework | =4.4.0.3.0 | |
Oracle Utilities Framework | =4.4.0.5.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Netapp Active Iq Unified Manager Linux | ||
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
Netapp Cloud Insights Acquisition Unit | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp Snap Creator Framework | ||
redhat/jackson-databind | <2.12.6.1 | 2.12.6.1 |
redhat/jackson-databind | <2.13.2.1 | 2.13.2.1 |
IBM Cognos Analytics 11.2.x | <=IBM Cognos Analytics 11.2.x | |
IBM Cognos Analytics 11.1.x | <=IBM Cognos Analytics 11.1.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this issue is CVE-2020-36518.
CVE-2020-36518 has a severity level of high (7).
CVE-2020-36518 causes a denial of service by exploiting a Java StackOverflow exception through the use of a large depth of nested objects.
Versions of jackson-databind before 2.13.0 are affected by CVE-2020-36518.
To fix CVE-2020-36518, update jackson-databind to version 2.13.0 or newer.