cbcvebase.
CVE-2018-14720
published 2019-01-02

CVE-2018-14720: FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianjackson-databind< jackson-databind 2.9.8-1 (bookworm)jackson-databind 2.9.8-1 (bookworm)
fasterxmljackson-databind
fasterxmljackson-databind
fasterxmljackson-databind
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.9.8-12.9.8-1
fasterxmljackson-databind>= 0 < 2.4.2-3ubuntu0.1~esm22.4.2-3ubuntu0.1~esm2
fasterxmljackson-databind>= 2.6.0 < 2.6.7.22.6.7.2
fasterxmljackson-databind>= 2.7.0 < 2.7.9.52.7.9.5
fasterxmljackson-databind>= 2.8.0 < 2.8.11.32.8.11.3
fasterxmljackson-databind>= 2.9.0 < 2.9.72.9.7
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclecommunications_billing_and_revenue_management
oraclecommunications_billing_and_revenue_management
oracleenterprise_manager_for_virtualization
oracleenterprise_manager_for_virtualization
oracleenterprise_manager_for_virtualization
oraclefinancial_services_analytical_applications_infrastructure

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL