← Back

CVE-2019-16943

nvd nist
Published: Oct 1, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

Affected (57)

Show all products
1 product
Jackson Databind
1 product
Debian Linux
1 product
Fedora
1 product
17 products
Banking Platform
Communications Calendar Server
Goldengate Application Adapters
Jd Edwards Enterpriseone Tools
Primavera Gateway
Retail Merchandising System
Retail Sales Audit
Trace File Analyzer
Webcenter Portal
Webcenter Sites
Weblogic Server
5 products
Active Iq Unified Manager
Oncommand Api Services
Oncommand Workflow Automation
Service Level Manager
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fasterxml
From 2.0.0 to 2.6.7.3
From 2.7.0 to 2.8.11.5
From 2.9.0 to 2.9.10.1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Configuration D
2 platform
Running on/withPlatform Versions
Redhat
Enterprise Linux Server
Version 6.0
Redhat
Enterprise Linux Server
Version 7.0
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Redhat
Version 7.2
Version 7.3
Running on/withPlatform Versions
Redhat
Enterprise Linux Server
Version 8.0
Configuration F
40 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 2.4.0
Version 2.4.1
Version 2.5.0
Version 2.6.0
Version 2.6.1
Version 2.6.2
Version 2.7.0
Version 2.7.1
Version 2.9.0
Oracle
Version 12.0.0.3.0
Version 7.5.0.23.0
Oracle
Version 8.0.0.2.0
Version 8.0.0.3.0
Version 1.2.1
Version 7.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 13.9.4.2.2
Version 19.1.0.0.0
Version 9.2
Version 9.2
Oracle
From 17.7 to 17.12.6
From 18.8.0 to 18.8.8
Version 16.1
Version 16.2
Version 19.12.0
Oracle
Version 15.0.3
Version 16.0.2
Version 16.0.3
Version 14.1
Up to 2.20.5
Oracle
Version 12.2.0.1
Version 18c
Version 19c
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Configuration G
7 vulnerable

References (52)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.