cbcvebase.
CVE-2018-11307
published 2019-07-09

CVE-2018-11307: An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianjackson-databind< jackson-databind 2.9.8-1 (bookworm)jackson-databind 2.9.8-1 (bookworm)
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.4.2-3ubuntu0.1~esm22.4.2-3ubuntu0.1~esm2
fasterxmljackson-databind>= 2.0.0 < 2.6.7.32.6.7.3
fasterxmljackson-databind>= 2.7.0 < 2.7.9.42.7.9.4
fasterxmljackson-databind>= 2.8.0 < 2.8.11.22.8.11.2
fasterxmljackson-databind>= 2.9.0 < 2.9.62.9.6
oracleclusterware
oraclecommunications_instant_messaging_server
oracleglobal_lifecycle_management_opatch< 11.2.0.3.2311.2.0.3.23
oracleglobal_lifecycle_management_opatch>= 12.2.0.1.0 < 12.2.0.1.1912.2.0.1.19
oracleglobal_lifecycle_management_opatch>= 13.9.4.0.0 < 13.9.4.2.113.9.4.2.1
oracleretail_customer_management_and_segmentation_foundation
oracleutilities_advanced_spatial_and_operational_analytics
redhatopenshift_container_platform
redhatopenshift_container_platform

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL