← Back

CVE-2020-9548

Published: Mar 2, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

Affected (46)

Show all products
1 product
Jackson Databind
1 product
Active Iq Unified Manager
1 product
Debian Linux
22 products
Agile Plm
Banking Digital Experience
Banking Platform
Communications Calendar Server
Communications Contacts Server
Communications Element Manager
Enterprise Manager Base Platform
Jd Edwards Enterpriseone Tools
Primavera Unifier
Retail Merchandising System
Retail Sales Audit
Retail Xstore Point Of Service
Weblogic Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fasterxml
From 2.0.0 to 2.7.9.7
From 2.8.0 to 2.8.11.6
From 2.9.0 to 2.9.10.4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
From 7.3
From 9.5
From 7.3
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration D
39 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.3.6
Version 21.0.2
Oracle
Version 18.1
Version 18.2
Version 18.3
Version 19.1
Version 19.2
Version 20.1
From 2.4.0 to 2.9.0
Version 8.0.0.4.0
Oracle
Version 8.0.0.4.0
Version 8.0.0.5.0
From 8.0.0 to 8.2.2
From 8.2.0 to 8.2.2
Version 7.1
Version 10.0.1.4.0
Oracle
From 12.0.0 to 12.0.3
Version 6.0.1
From 8.2.0 to 8.2.2
From 8.2.0 to 8.2.2
Oracle
Version 13.3.0.0
Version 13.4.0.0
Before 12.2.0.1.20
Before 9.2.4.2
Before 9.2.4.2
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 19.12
Version 15.0
Version 14.1
Oracle
Version 15.0
Version 16.0
Version 17.0
Version 18.0
Version 19.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (32)

Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.