← Back

CVE-2020-11619

nvd nist
Published: Apr 7, 2020Modified: Apr 29, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

Affected (35)

Show all products
1 product
Jackson Databind
1 product
Debian Linux
2 products
Active Iq Unified Manager
17 products
Agile Plm
Banking Platform
Communications Calendar Server
Communications Contacts Server
Enterprise Manager Base Platform
Jd Edwards Enterpriseone Tools
Primavera Unifier
Retail Merchandising System
Retail Sales Audit
Retail Xstore Point Of Service
Weblogic Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.9.10.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
4 vulnerable
Configuration D
29 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.3.6
From 2.4.0 to 2.9.0
Version 8.0.0.4.0
Oracle
Version 8.0.0.4.0
Version 8.0.0.5.0
From 8.0.0 to 8.2.2
Version 7.1
Version 10.0.1.4.0
Oracle
From 12.0.0 to 12.0.3
Version 6.0.1
Oracle
Version 13.3.0.0
Version 13.4.0.0
Before 12.2.0.1.20
Before 9.2.4.2
Before 9.2.4.2
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 19.12
Version 15.0
Version 14.1
Oracle
Version 15.0
Version 16.0
Version 17.0
Version 18.0
Version 19.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (16)

Source: cve@mitre.org
Issue TrackingPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.