ZeroHour

CVE-2018-14719

CVSS 3.1
9.8 critical
EPSS
10%p95
Published
()
Modified
Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

Vendors
fasterxmldebianoracleredhatnetapp
Products
jackson-databind, debian linux, banking platform, business process management suite, clusterware, communications billing and revenue management, database server, enterprise manager for virtualization, financial services analytical applications infrastructure, global lifecycle management opatch, jdeveloper, primavera p6 enterprise project portfolio management
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.