cbcvebase.
CVE-2018-1000873
published 2018-12-20

CVE-2018-1000873: Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.

Affected

13 ranges
VendorProductVersion rangeFixed in
fasterxmljackson-modules-java8< 2.9.82.9.8
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
oracleclusterware
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracleglobal_lifecycle_management_opatch< 11.2.0.3.2311.2.0.3.23
oracleglobal_lifecycle_management_opatch>= 12.2.0.1.0 < 12.2.0.1.1912.2.0.1.19
oracleglobal_lifecycle_management_opatch>= 13.9.4.0.0 < 13.9.4.2.113.9.4.2.1
oraclenosql_database< 19.3.1219.3.12
redhatjboss_enterprise_application_platform

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL