CVE-2019-12086

Severity
7.5HIGH
EPSS
15.5%
top 5.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 24

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDfasterxml/jackson-databind2.0.02.6.7.3+3
Debianjackson-databind< 2.9.8-2+3
Ubuntujackson-databind< 2.4.2-3ubuntu0.1~esm2

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

6
GHSA
Deserialization of Untrusted Data in org.codehaus.jackson:jackson-mapper-asl2022-05-24
OSV
jackson-databind vulnerabilities2021-03-15
OSV
Information exposure in FasterXML jackson-databind2019-05-23
GHSA
Information exposure in FasterXML jackson-databind2019-05-23
CVEList
CVE-2019-12086: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 22019-05-17

📋Vendor Advisories

7
Oracle
Oracle Oracle GoldenGate Risk Matrix: Internal Framework (jackson-databind) — CVE-2019-120862022-04-15
Ubuntu
Jackson Databind vulnerabilities2021-03-15
Oracle
Oracle Oracle Retail Applications Risk Matrix: Segment (jackson-databind) — CVE-2019-120862020-07-15
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 IOT Orchestrator Security (jackson-databind) — CVE-2019-120862020-01-15
Red Hat
codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities2019-09-30

💬Community

3
Bugzilla
CVE-2019-10202 codehaus: incomplete fix for unsafe deserialization in jackson-databind vulnerabilities2019-07-18
Bugzilla
CVE-2019-12086 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server. [fedora-all]2019-05-23
Bugzilla
CVE-2019-12086 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server.2019-05-23
CVE-2019-12086 (HIGH CVSS 7.5) | A Polymorphic Typing issue was disc | cvebase.io