ZeroHour

CVE-2018-14721

CVSS 3.0
10.0 critical
EPSS
10%p95
Published
()
Modified
Description

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

Vendors
fasterxmldebianoracleredhat
Products
jackson-databind, debian linux, banking platform, communications billing and revenue management, enterprise manager for virtualization, financial services analytical applications infrastructure, jdeveloper, primavera unifier, retail merchandising system, webcenter portal, jboss enterprise application platform, openshift container platform
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.