CVE-2019-20330
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Affected (53)
Products: Fasterxml: Jackson Databind · Oracle: Banking Platform, Communications Billing And Revenue Management, Communications Cloud Native Core Network Slice Selection Function, Communications Contacts Server, Communications Evolved Communications Application Server, Communications Instant Messaging Server, Communications Network Charging And Control, Customer Management And Segmentation Foundation, Enterprise Manager Base Platform, Global Lifecycle Management Opatch, Goldengate Application Adapters, Goldengate Stream Analytics, Jd Edwards Enterpriseone Orchestrator, Jd Edwards Enterpriseone Tools, Primavera Unifier, Retail Merchandising System, Retail Sales Audit, Retail Xstore Point Of Service, Siebel Engineering Installer & Deployment, Siebel Ui Framework, Trace File Analyzer, Webcenter Portal, Weblogic Server · Debian: Debian Linux · +1 more
Show all products
Fasterxml: Jackson Databind · Oracle: Banking Platform, Communications Billing And Revenue Management, Communications Cloud Native Core Network Slice Selection Function, Communications Contacts Server, Communications Evolved Communications Application Server, Communications Instant Messaging Server, Communications Network Charging And Control, Customer Management And Segmentation Foundation, Enterprise Manager Base Platform, Global Lifecycle Management Opatch, Goldengate Application Adapters, Goldengate Stream Analytics, Jd Edwards Enterpriseone Orchestrator, Jd Edwards Enterpriseone Tools, Primavera Unifier, Retail Merchandising System, Retail Sales Audit, Retail Xstore Point Of Service, Siebel Engineering Installer & Deployment, Siebel Ui Framework, Trace File Analyzer, Webcenter Portal, Weblogic Server · Debian: Debian Linux · Netapp: Active Iq Unified Manager, Oncommand Api Services, Service Level Manager, Snapcenter, Steelstore Cloud Integrated Storage
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.7.9.7 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.4.0 to 2.9.0 | |
| Version 12.0.0.3.0 | |
| Version 1.2.1 | |
| Version 8.0.0.4.0 | |
| Version 7.1 | |
| Version 10.0.1.4.0 | |
| From 12.0.0 to 12.0.3 | |
| Version 18.0 | |
| Version 13.3.0.0 | |
| Before 11.2.0.3.23 | |
| Version 19.1.0.0.0 | |
| Before 19.1.0.0.1 | |
| Before 9.2.4.2 | |
| Before 9.2.4.2 | |
| From 17.7 to 17.12 | |
| Version 15.0.3 | |
| Version 14.1 | |
| Version 15.0 | |
| Up to 2.20.5 | |
| Up to 20.5 | |
| Version 12.2.0.1 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.3 | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
References (66)
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.