CVE-2020-14195
published 2020-06-16CVE-2020-14195: FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to…
PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
4.55%
90.5th percentile
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jackson-databind | < jackson-databind 2.11.1-1 (bookworm) | jackson-databind 2.11.1-1 (bookworm) |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.4.2-3ubuntu0.1~esm2 | 2.4.2-3ubuntu0.1~esm2 |
| fasterxml | jackson-databind | >= 2.9.0 < 2.9.10.5 | 2.9.10.5 |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| oracle | agile_plm | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | communications_calendar_server | — | — |
| oracle | communications_contacts_server | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.2.2 | — |
| oracle | communications_element_manager | 8.2.0 – 8.2.2 | — |
| oracle | communications_evolved_communications_application_server | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | communications_session_report_manager | 8.2.0 – 8.2.2 | — |
| oracle | communications_session_route_manager | 8.2.0 – 8.2.2 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Managing Messages (jackson-databind) — CVE-2020-14195
vendor_oracle·2021-07-15·CVSS 8.1
CVE-2020-14195 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Managing Messages (jackson-databind) — CVE-2020-14195
Oracle Oracle Communications Applications Risk Matrix: Managing Messages (jackson-databind) vulnerability
CVE: CVE-2020-14195
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Siebel CRM Risk Matrix: EAI (jackson-databind) — CVE-2020-14195
vendor_oracle·2021-04-15·CVSS 8.1
CVE-2020-14195 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: EAI (jackson-databind) — CVE-2020-14195
Oracle Oracle Siebel CRM Risk Matrix: EAI (jackson-databind) vulnerability
CVE: CVE-2020-14195
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Ubuntu
Jackson Databind vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 9.8
CVE-2019-14540 [CRITICAL] Jackson Databind vulnerabilities
Title: Jackson Databind vulnerabilities
Summary: Several security issues were fixed in Jackson Databind.
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-109
Oracle
Oracle Oracle Communications Applications Risk Matrix: REST API (jackson-databind) — CVE-2020-14195
vendor_oracle·2021-01-15·CVSS 8.1
CVE-2020-14195 [HIGH] Oracle Oracle Communications Applications Risk Matrix: REST API (jackson-databind) — CVE-2020-14195
Oracle Oracle Communications Applications Risk Matrix: REST API (jackson-databind) vulnerability
CVE: CVE-2020-14195
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (jackson-databind) — CVE-2020-14195
vendor_oracle·2020-10-15·CVSS 8.1
CVE-2020-14195 [HIGH] Oracle Oracle Communications Risk Matrix: IDIH (jackson-databind) — CVE-2020-14195
Oracle Oracle Communications Risk Matrix: IDIH (jackson-databind) vulnerability
CVE: CVE-2020-14195
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Red Hat
jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
vendor_redhat·2020-06-14·CVSS 8.1
CVE-2020-14195 [HIGH] CWE-502 jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.5. FasterXML jackson-databind mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: While OpenShift Container Platform's elasticsearch plugins do ship the vulnerable component, it doesn't do any of the unsafe things described in https://access.redhat.com/solutions/3279231. We may update the jackson-databind dependency
Debian
CVE-2020-14195: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee...
vendor_debian·2020·CVSS 8.1
CVE-2020-14195 [HIGH] CVE-2020-14195: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction betwee...
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
Scope: local
bookworm: resolved (fixed in 2.11.1-1)
bullseye: resolved (fixed in 2.11.1-1)
forky: resolved (fixed in 2.11.1-1)
sid: resolved (fixed in 2.11.1-1)
trixie: resolved (fixed in 2.11.1-1)
OSV
jackson-databind vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-11307 [CRITICAL] jackson-databind vulnerabilities
jackson-databind vulnerabilities
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,
CVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2
GHSA
Deserialization of untrusted data in Jackson Databind
ghsa·2020-06-18
CVE-2020-14195 [HIGH] CWE-502 Deserialization of untrusted data in Jackson Databind
Deserialization of untrusted data in Jackson Databind
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
OSV
Deserialization of untrusted data in Jackson Databind
osv·2020-06-18
CVE-2020-14195 [HIGH] Deserialization of untrusted data in Jackson Databind
Deserialization of untrusted data in Jackson Databind
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
OSV
CVE-2020-14195: FasterXML jackson-databind 2
osv·2020-06-16·CVSS 8.1
CVE-2020-14195 [HIGH] CVE-2020-14195: FasterXML jackson-databind 2
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
No detection rules found.
No public exploits indexed.
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2020-14195 jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
bugzilla·2020-06-19·CVSS 8.1
CVE-2020-14195 [HIGH] CVE-2020-14195 jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
CVE-2020-14195 jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory
A vulnerability was found in FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory.
References:
https://github.com/FasterXML/jackson-databind/issues/2765
Discussion:
Created jackson-databind tracking bugs for this issue:
Affects: fedora-all [bug 1848959]
---
Mitigation:
The following conditions are needed for an exploit, we recommend avoiding all if possible:
* Deserialization from sources you do not control
* enableDefaultTyping()
* @JsonTypeInfo using id.CLASS or id.MINIMAL_CLASS
* org.jsecurity.realm.jndi.JndiRealmFactory in classpath
---
Statement:
While OpenShift Contain
Bugzilla
CVE-2020-14195 jackson-databind: mishandling of interaction between serialization gadgets and typing [fedora-all]
bugzilla·2020-06-19·CVSS 8.1
CVE-2020-14195 [HIGH] CVE-2020-14195 jackson-databind: mishandling of interaction between serialization gadgets and typing [fedora-all]
CVE-2020-14195 jackson-databind: mishandling of interaction between serialization gadgets and typing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
https://github.com/FasterXML/jackson-databind/issues/2765https://lists.debian.org/debian-lts-announce/2020/07/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20200702-0003/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/FasterXML/jackson-databind/issues/2765https://lists.debian.org/debian-lts-announce/2020/07/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20200702-0003/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-06-16
Published