CVE-2020-36518
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Affected (77)
Products: Fasterxml: Jackson Databind · Oracle: Big Data Spatial And Graph, Coherence, Commerce Platform, Communications Billing And Revenue Management, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Console, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Service Communication Proxy, Communications Cloud Native Core Unified Data Repository, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Crime And Compliance Management Studio, Financial Services Enterprise Case Management, Financial Services Trade Based Anti Money Laundering, Global Lifecycle Management Nextgen Oui Framework, Global Lifecycle Management Opatch, Graph Server And Client, Health Sciences Empirica Signal, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera P6 Enterprise Project Portfolio Management, Primavera Unifier, Retail Sales Audit, Sd Wan Edge, Spatial Studio, Utilities Framework, Weblogic Server · Debian: Debian Linux · +1 more
Show all products
Fasterxml: Jackson Databind · Oracle: Big Data Spatial And Graph, Coherence, Commerce Platform, Communications Billing And Revenue Management, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Console, Communications Cloud Native Core Network Repository Function, Communications Cloud Native Core Network Slice Selection Function, Communications Cloud Native Core Security Edge Protection Proxy, Communications Cloud Native Core Service Communication Proxy, Communications Cloud Native Core Unified Data Repository, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Crime And Compliance Management Studio, Financial Services Enterprise Case Management, Financial Services Trade Based Anti Money Laundering, Global Lifecycle Management Nextgen Oui Framework, Global Lifecycle Management Opatch, Graph Server And Client, Health Sciences Empirica Signal, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera P6 Enterprise Project Portfolio Management, Primavera Unifier, Retail Sales Audit, Sd Wan Edge, Spatial Studio, Utilities Framework, Weblogic Server · Debian: Debian Linux · Netapp: Active Iq Unified Manager, Cloud Insights Acquisition Unit, Oncommand Insight, Oncommand Workflow Automation, Snap Creator Framework
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.12.6.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 23.1 | |
| Version 14.1.1.0.0 | |
| Version 11.3.0 | |
| From 12.0.0.4.0 to 12.0.0.6.0 | |
| Version 22.1.3 | |
| Version 1.9.0 | |
| Version 22.1.2 | |
| Version 22.1.0 | |
| Version 22.1.1 | |
| Version 22.2.0 | |
| Version 22.2.0 | |
| From 8.0.7 to 8.1.0.0 | |
| From 8.1.1.0 to 8.1.2.1 | |
| Version 8.0.8.2.0 | |
| From 8.1.1.0 to 8.1.2.1 | |
| Version 8.0.7 | |
| Before 13.9.4.2.2 | |
| Before 12.2.0.1.30 | |
| Before 22.2.0 | |
| Version 9.1.0.5.2 | |
| Version 8.58 | |
| From 17.12.0 to 17.12.11 | |
| From 17.12.0.0 to 17.12.20.4 | |
| From 17.0 to 17.12 | |
| Version 15.0.3.1 | |
| Version 9.0 | |
| Before 20.1.0 | |
| Version 4.3.0.5.0 | |
| Version 12.2.1.3.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
References (14)
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.