CVE-2020-36518
published 2022-03-11CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.86%
91.0th percentile
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_software | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | jackson-databind | < jackson-databind 2.13.2.2-1 (bookworm) | jackson-databind 2.13.2.2-1 (bookworm) |
| fasterxml | jackson-databind | < 2.12.6.1 | 2.12.6.1 |
| fasterxml | jackson-databind | >= 0 < 2.12.1-1+deb11u1 | 2.12.1-1+deb11u1 |
| fasterxml | jackson-databind | >= 0 < 2.13.2.2-1 | 2.13.2.2-1 |
| fasterxml | jackson-databind | >= 0 < 2.13.2.2-1 | 2.13.2.2-1 |
| fasterxml | jackson-databind | >= 0 < 2.13.2.2-1 | 2.13.2.2-1 |
| fasterxml | jackson-databind | >= 2.13.0 < 2.13.2.1 | 2.13.2.1 |
| oracle | big_data_spatial_and_graph | < 23.1 | 23.1 |
| oracle | coherence | — | — |
| oracle | commerce_platform | — | — |
| oracle | commerce_platform | — | — |
| oracle | commerce_platform | — | — |
| oracle | communications_billing_and_revenue_management | 12.0.0.4.0 – 12.0.0.6.0 | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2020-36518: DoS (Denial of Service) com.fasterxml.jackson.core in Jira Software Data Center and Server
vendor_atlassian·2023-11-21·CVSS 7.5
CVE-2020-36518 [HIGH] CVE-2020-36518: DoS (Denial of Service) com.fasterxml.jackson.core in Jira Software Data Center and Server
CVE-2020-36518: DoS (Denial of Service) com.fasterxml.jackson.core in Jira Software Data Center and Server
DoS (Denial of Service) com.fasterxml.jackson.core in Jira Software Data Center and Server
CVE: CVE-2020-36518
Severity: HIGH
Affected products: Jira Software
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Event Management (jackson-databind) — CVE-2020-36518
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2020-36518 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Event Management (jackson-databind) — CVE-2020-36518
Oracle Oracle Enterprise Manager Risk Matrix: Event Management (jackson-databind) vulnerability
CVE: CVE-2020-36518
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (jackson-databind) — CVE-2020-36518
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2020-36518 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (jackson-databind) — CVE-2020-36518
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (jackson-databind) vulnerability
CVE: CVE-2020-36518
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (jackson-databind) — CVE-2020-36518
vendor_oracle·2023-04-15·CVSS 6.5
CVE-2020-36518 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (jackson-databind) — CVE-2020-36518
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (jackson-databind) vulnerability
CVE: CVE-2020-36518
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle GoldenGate Risk Matrix: GoldenGate Stream Analytics (jackson-databind) — CVE-2020-36518
vendor_oracle·2023-01-15·CVSS 6.5
CVE-2020-36518 [HIGH] Oracle Oracle GoldenGate Risk Matrix: GoldenGate Stream Analytics (jackson-databind) — CVE-2020-36518
Oracle Oracle GoldenGate Risk Matrix: GoldenGate Stream Analytics (jackson-databind) vulnerability
CVE: CVE-2020-36518
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Database - Fleet Patching (jackson-databind) — CVE-2020-36518
vendor_oracle·2022-10-15·CVSS 6.5
CVE-2020-36518 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Database - Fleet Patching (jackson-databind) — CVE-2020-36518
Oracle Oracle Database Server Risk Matrix: Oracle Database - Fleet Patching (jackson-databind) vulnerability
CVE: CVE-2020-36518
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (jackson-databind) — CVE-2020-36518
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2020-36518 [HIGH] Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (jackson-databind) — CVE-2020-36518
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (jackson-databind) vulnerability
CVE: CVE-2020-36518
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (jackson-databind) — CVE-2020-36518
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2020-36518 [HIGH] Oracle Oracle Communications Risk Matrix: CNC Console (jackson-databind) — CVE-2020-36518
Oracle Oracle Communications Risk Matrix: CNC Console (jackson-databind) vulnerability
CVE: CVE-2020-36518
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
jackson-databind: denial of service via a large depth of nested objects
vendor_redhat·2020-08-13·CVSS 7.5
CVE-2020-36518 [HIGH] CWE-400 jackson-databind: denial of service via a large depth of nested objects
jackson-databind: denial of service via a large depth of nested objects
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
A flaw was found in the Jackson Databind package. This cause of the issue is due to a Java StackOverflow exception and a denial of service via a significant depth of nested objects.
Statement: CodeReady Studio is no longer supported and therefore this flaw will not be addressed in CodeReady Studio.
Package: jackson-databind (A-MQ Clients 2) - Not affected
Package: jackson-databind (Red Hat A-MQ Online) - Not affected
Package: jackson-databind (Red Hat BPM Suite 6) - Out of support scope
Package: jackson-databind (Red Hat build of Apicurio Registry 2) - Affected
Package: jackson-databin
Debian
CVE-2020-36518: jackson-databind - jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial ...
vendor_debian·2020·CVSS 7.5
CVE-2020-36518 [HIGH] CVE-2020-36518: jackson-databind - jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial ...
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Scope: local
bookworm: resolved (fixed in 2.13.2.2-1)
bullseye: resolved (fixed in 2.12.1-1+deb11u1)
forky: resolved (fixed in 2.13.2.2-1)
sid: resolved (fixed in 2.13.2.2-1)
trixie: resolved (fixed in 2.13.2.2-1)
GHSA
Apiman Manager API affected by Jackson denial of service vulnerability
ghsa·2023-01-09·CVSS 7.5
[HIGH] CWE-787 Apiman Manager API affected by Jackson denial of service vulnerability
Apiman Manager API affected by Jackson denial of service vulnerability
### Impact
Due to a vulnerability in `jackson-databind <= 2.12.6.0`, an authenticated attacker could craft an Apiman policy configuration which, when saved, may cause a denial of service on the Apiman Manager API.
This does **not** affect the Apiman Gateway.
### Patches
Upgrade to Apiman 3.0.0.Final or later.
If you are using an older version of Apiman and need to remain on that version, contact your Apiman [support provider](https://www.apiman.io/support.html) for advice/long-term support.
### Workarounds
If all users of the Apiman Manager are trusted then you may assess this is low risk, as an account is required to exploit the vulnerability.
### References
* Apiman maintainer and security contact: marc@blac
OSV
Apiman Manager API affected by Jackson denial of service vulnerability
osv·2023-01-09·CVSS 7.5
[HIGH] Apiman Manager API affected by Jackson denial of service vulnerability
Apiman Manager API affected by Jackson denial of service vulnerability
### Impact
Due to a vulnerability in `jackson-databind <= 2.12.6.0`, an authenticated attacker could craft an Apiman policy configuration which, when saved, may cause a denial of service on the Apiman Manager API.
This does **not** affect the Apiman Gateway.
### Patches
Upgrade to Apiman 3.0.0.Final or later.
If you are using an older version of Apiman and need to remain on that version, contact your Apiman [support provider](https://www.apiman.io/support.html) for advice/long-term support.
### Workarounds
If all users of the Apiman Manager are trusted then you may assess this is low risk, as an account is required to exploit the vulnerability.
### References
* Apiman maintainer and security contact: marc@blac
GHSA
Deeply nested json in jackson-databind
ghsa·2022-03-12
CVE-2020-36518 [HIGH] CWE-787 Deeply nested json in jackson-databind
Deeply nested json in jackson-databind
jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects.
OSV
Deeply nested json in jackson-databind
osv·2022-03-12
CVE-2020-36518 [HIGH] Deeply nested json in jackson-databind
Deeply nested json in jackson-databind
jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects.
OSV
CVE-2020-36518: jackson-databind before 2
osv·2022-03-11·CVSS 7.5
CVE-2020-36518 [HIGH] CVE-2020-36518: jackson-databind before 2
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
No detection rules found.
No public exploits indexed.
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
blogs_tenable·2022-07-20
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://github.com/FasterXML/jackson-databind/issues/2816https://lists.debian.org/debian-lts-announce/2022/05/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2022/11/msg00035.htmlhttps://security.netapp.com/advisory/ntap-20220506-0004/https://www.debian.org/security/2022/dsa-5283https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/FasterXML/jackson-databind/issues/2816https://lists.debian.org/debian-lts-announce/2022/05/msg00001.htmlhttps://lists.debian.org/debian-lts-announce/2022/11/msg00035.htmlhttps://security.netapp.com/advisory/ntap-20220506-0004/https://www.debian.org/security/2022/dsa-5283https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-03-11
Published