CVE-2019-17531
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.
Affected (48)
Products: Fasterxml: Jackson Databind · Debian: Debian Linux · Redhat: Jboss Enterprise Application Platform · +2 more
Show all products
Fasterxml: Jackson Databind · Debian: Debian Linux · Redhat: Jboss Enterprise Application Platform · Oracle: Banking Platform, Communications Billing And Revenue Management, Communications Calendar Server, Communications Cloud Native Core Network Slice Selection Function, Communications Evolved Communications Application Server, Global Lifecycle Management Nextgen Oui Framework, Goldengate Application Adapters, Jd Edwards Enterpriseone Orchestrator, Jd Edwards Enterpriseone Tools, Primavera Gateway, Retail Merchandising System, Retail Sales Audit, Siebel Engineering Installer & Deployment, Trace File Analyzer, Webcenter Portal, Webcenter Sites, Weblogic Server · Netapp: Oncommand Workflow Automation, Steelstore Cloud Integrated Storage
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.6.7.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.2 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux Server | Version 6.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.4.0 | |
| Version 12.0.0.3.0 | |
| Version 8.0.0.2.0 | |
| Version 1.2.1 | |
| Version 7.1 | |
| Version 12.2.1.3.0 | |
| Version 19.1.0.0.0 | |
| Version 9.2 | |
| Version 9.2 | |
| From 17.7 to 17.12.6 | |
| Version 15.0.3 | |
| Version 14.1 | |
| Up to 2.20.5 | |
| Version 12.2.0.1 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
References (38)
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.