CVE-2018-14719
—CVSS 3.1
9.8 critical
EPSS
10%p95
Published
()
Modified
Description
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
- Vendors
- fasterxmldebianoracleredhatnetapp
- Products
- jackson-databind, debian linux, banking platform, business process management suite, clusterware, communications billing and revenue management, database server, enterprise manager for virtualization, financial services analytical applications infrastructure, global lifecycle management opatch, jdeveloper, primavera p6 enterprise project portfolio management
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.