CVE-2019-14379
CWE-1321 — Prototype PollutionCWE-915CWE-502 — Deserialization of Untrusted Data15 documents10 sources
Severity
9.8CRITICAL
EPSS
1.5%
top 19.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 29
Latest updateMar 14
Description
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages20 packages
Also affects: Debian Linux 8.0, Fedora 29, 30, 31, Openshift Container Platform 3.11, 4.1
Patches
🔴Vulnerability Details
5📋Vendor Advisories
7Oracle▶
Oracle Oracle GoldenGate Risk Matrix: Security / Application Adapters (jackson-databind, SLF4J, ZooKeeper, Apache Spark) — CVE-2019-14379↗2020-07-15
Oracle▶
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (jackson-databind) — CVE-2019-14379↗2020-04-15
Oracle▶
Oracle Oracle Communications Applications Risk Matrix: Presence-api (jackson-databind) — CVE-2019-14379↗2020-01-15