CVE-2018-14720
—CVSS 3.0
9.8 critical
EPSS
8%p94
Published
()
Modified
Description
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
- Vendors
- fasterxmldebianoracleredhat
- Products
- jackson-databind, debian linux, banking platform, communications billing and revenue management, enterprise manager for virtualization, financial services analytical applications infrastructure, jdeveloper, primavera unifier, retail merchandising system, webcenter portal, jboss enterprise application platform, openshift container platform
- Weakness
- CWE-502, CWE-611
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.