ZeroHour

CVE-2020-35491

PoC
CVSS 3.1
8.1 high
EPSS
10%p95
Published
()
Modified
Description

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

Vendors
fasterxmlnetappdebianoracle
Products
jackson-databind, service level manager, debian linux, agile product lifecycle management, application testing suite, autovue for agile product lifecycle management, banking platform, banking treasury management, banking virtual account management, blockchain platform, communications cloud native core policy, communications cloud native core unified data repository
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.