ZeroHour

CVE-2018-14718

CVSS 3.1
9.8 critical
EPSS
13%p96
Published
()
Modified
Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

Vendors
fasterxmldebianoraclenetappredhat
Products
jackson-databind, debian linux, banking platform, business process management suite, communications billing and revenue management, communications instant messaging server, enterprise manager for virtualization, financial services analytical applications infrastructure, global lifecycle management opatch, jd edwards enterpriseone orchestrator, jd edwards enterpriseone tools, jdeveloper
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.