cbcvebase.
CVE-2018-7489
published 2018-02-26

CVE-2018-7489: FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete…

PriorityP272critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
20.14%
97.2th percentile
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

Affected

17 ranges
VendorProductVersion rangeFixed in
apachetika
debiandebian_linux
debiandebian_linux
debianjackson-databind< jackson-databind 2.9.5-1 (bookworm)jackson-databind 2.9.5-1 (bookworm)
fasterxmljackson-databind< 2.7.9.32.7.9.3
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 0 < 2.9.5-12.9.5-1
fasterxmljackson-databind>= 2.8.0 < 2.8.11.12.8.11.1
fasterxmljackson-databind>= 2.9.0 < 2.9.52.9.5
oraclecommunications_billing_and_revenue_management
oraclecommunications_billing_and_revenue_management
oraclecommunications_instant_messaging_server
redhatjboss_enterprise_application_platform
redhatjboss_enterprise_application_platform
redhatjboss_enterprise_application_platform

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires sending maliciously crafted JSON input to the readValue method of the ObjectMapper, exploitable when c3p0 libraries are present in the classpath
  • Exploit leverages the c3p0 gadget chain for polymorphic deserialization; detect use of c3p0 classes in conjunction with jackson-databind polymorphic type handling
  • Upstream patch commit for CVE-2018-7489 in jackson-databind can be used to verify patched vs. unpatched versions
  • ·Vulnerability only exploitable if c3p0 libraries are present in the classpath alongside jackson-databind; environments without c3p0 are not affected
  • ·Polymorphic type handling must be enabled (e.g., enableDefaultTyping(), @JsonTypeInfo with Id.CLASS or Id.MINIMAL_CLASS) for the vulnerability to be exploitable
  • ·Satellite 6.2 is not affected because it does not support c3p0 classes; Satellite 6.3 and 6.4 are not affected because Candlepin does not use polymorphic deserialization
  • ·Fixed in jackson-databind 2.7.9.3, 2.8.11.1, and 2.9.5; versions before these are vulnerable

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_apache9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.