← Back

CVE-2018-14718

nvd nist
Published: Jan 2, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

Affected (57)

Show all products
1 product
Jackson Databind
1 product
Debian Linux
19 products
Banking Platform
Business Process Management Suite
Jd Edwards Enterpriseone Tools
Jdeveloper
Nosql Database
Primavera Unifier
Retail Merchandising System
Siebel Ui Framework
Webcenter Portal
3 products
Oncommand Workflow Automation
Snapcenter
1 product
Openshift Container Platform
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Fasterxml
From 2.0.0 to 2.6.7.3
From 2.7.0 to 2.7.9.5
From 2.8.0 to 2.8.11.3
From 2.9.0 to 2.9.7
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Configuration C
44 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 2.5.0
Version 2.6.0
Version 2.6.1
Version 2.6.2
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Oracle
Version 12.0
Version 7.5
Version 10.0.1.3.0
Oracle
Version 13.2.2
Version 13.2.3
Version 13.3.1
Oracle
Version 8.0.2
Version 8.0.3
Version 8.0.4
Version 8.0.5
Version 8.0.6
Version 8.0.7
Oracle
Before 11.2.0.3.23
From 12.2.0.1.0 to 12.2.0.1.19
From 13.9.4.0.0 to 13.9.4.2.1
Version 9.2
Version 9.2
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Oracle
Before 19.3.12
Version 19.3.12
Oracle
From 17.7 to 17.12
Version 15.1
Version 15.2
Version 16.1
Version 16.2
Version 18.8
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 17.0
Oracle
Version 15.0
Version 16.0
Version 1.60.9.0.0
Up to 19.8
Up to 19.10
Version 12.2.1.3.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
From 3.11 to 3.11.153
From 4.6 to 4.6.26
Version 3.10
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.1 to 4.1.18
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0

References (70)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchRelease NotesThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.