← Back

CVE-2019-17531

nvd nist
Published: Oct 12, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload.

Affected (48)

Show all products
1 product
Jackson Databind
1 product
Debian Linux
1 product
17 products
Banking Platform
Communications Calendar Server
Goldengate Application Adapters
Jd Edwards Enterpriseone Tools
Primavera Gateway
Retail Merchandising System
Retail Sales Audit
Trace File Analyzer
Webcenter Portal
Webcenter Sites
Weblogic Server
2 products
Oncommand Workflow Automation
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fasterxml
From 2.0.0 to 2.6.7.3
From 2.7.0 to 2.8.11.5
From 2.9.0 to 2.9.10.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
2 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Redhat
Version 7.2
Version 7.3
Running on/withPlatform Versions
Redhat
Enterprise Linux Server
Version 6.0
Redhat
Enterprise Linux Server
Version 7.0
Redhat
Enterprise Linux Server
Version 8.0
Configuration D
40 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 2.4.0
Version 2.4.1
Version 2.5.0
Version 2.6.0
Version 2.6.1
Version 2.6.2
Version 2.7.0
Version 2.7.1
Version 2.9.0
Oracle
Version 12.0.0.3.0
Version 7.5.0.23.0
Oracle
Version 8.0.0.2.0
Version 8.0.0.3.0
Version 1.2.1
Version 7.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 13.9.4.2.2
Version 19.1.0.0.0
Version 9.2
Version 9.2
Oracle
From 17.7 to 17.12.6
From 18.8.0 to 18.8.8
Version 16.1
Version 16.2
Version 19.12.0
Oracle
Version 15.0.3
Version 16.0.2
Version 16.0.3
Version 14.1
Up to 2.20.5
Oracle
Version 12.2.0.1
Version 18c
Version 19c
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions

References (38)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.