← Back

CVE-2017-15095

nvd nist
Published: Feb 6, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

Affected (52)

Show all products
1 product
Jackson Databind
1 product
Debian Linux
4 products
Openshift Container Platform
Satellite
Satellite Capsule
4 products
Oncommand Balance
Oncommand Performance Manager
Oncommand Shift
Snapcenter
14 products
Banking Platform
Clusterware
Database Server
Identity Manager
Jd Edwards Enterpriseone Tools
Primavera Unifier
Webcenter Portal
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Fasterxml
From 2.0.0 to 2.6.7.2
From 2.7.0 to 2.7.9.2
From 2.8.0 to 2.8.10
Version 2.9.0
Version 2.9.0 prerelease1
Version 2.9.0 prerelease2
Version 2.9.0 prerelease3
Version 2.9.0 prerelease4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.11
Version 6.4
Version 6.4
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.1
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0.0
Version 6.4.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 5.0
Configuration F
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 7.1.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0
Redhat
Enterprise Linux
Version 7.0
Configuration G
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Netapp
All versions
All versions
All versions
All versions
Configuration H
30 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 2.5.0
Version 2.6.0
Version 2.6.1
Version 2.6.2
Version 12.1.0.2.0
Oracle
Version 12.0
Version 7.5
Before 8.3
Version 10.0.1.2.0
Oracle
Version 12.2.0.1
Version 18.1
Oracle
Version 13.2.2
Version 13.2.3
Version 13.3.1
Oracle
Version 8.0.2
Version 8.0.3
Version 8.0.4
Version 8.0.5
Version 8.0.6
Version 8.0.7
Before 12.2.0.1.14
Oracle
Version 11.1.2.3.0
Version 12.2.1.3.0
Version 9.2
Oracle
From 17.1 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 2.7.0.1
Version 12.2.1.3.0

References (64)

Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.