CVE-2020-9546
published 2020-03-02CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.61%
90.7th percentile
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jackson-databind | < jackson-databind 2.11.1-1 (bookworm) | jackson-databind 2.11.1-1 (bookworm) |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.11.1-1 | 2.11.1-1 |
| fasterxml | jackson-databind | >= 0 < 2.4.2-3ubuntu0.1~esm2 | 2.4.2-3ubuntu0.1~esm2 |
| fasterxml | jackson-databind | >= 2.0.0 < 2.7.9.7 | 2.7.9.7 |
| fasterxml | jackson-databind | >= 2.8.0 < 2.8.11.6 | 2.8.11.6 |
| fasterxml | jackson-databind | >= 2.9.0 < 2.9.10.4 | 2.9.10.4 |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| oracle | agile_plm | — | — |
| oracle | autovue_for_agile_product_lifecycle_management | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_platform | 2.4.0 – 2.9.0 | — |
| oracle | communications_calendar_server | — | — |
| oracle | communications_contacts_server | — | — |
| oracle | communications_contacts_server | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.2.2 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Jackson Databind vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 9.8
CVE-2019-14540 [CRITICAL] Jackson Databind vulnerabilities
Title: Jackson Databind vulnerabilities
Summary: Several security issues were fixed in Jackson Databind.
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-109
Oracle
Oracle Oracle Retail Applications Risk Matrix: Foundation (jackson-databind) — CVE-2020-9546
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2020-9546 [CRITICAL] Oracle Oracle Retail Applications Risk Matrix: Foundation (jackson-databind) — CVE-2020-9546
Oracle Oracle Retail Applications Risk Matrix: Foundation (jackson-databind) vulnerability
CVE: CVE-2020-9546
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jackson-databind) — CVE-2020-9546
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2020-9546 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jackson-databind) — CVE-2020-9546
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jackson-databind) vulnerability
CVE: CVE-2020-9546
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Global Lifecycle Management Risk Matrix: Patch Installer (jackson-databind) — CVE-2020-9546
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2020-9546 [CRITICAL] Oracle Oracle Global Lifecycle Management Risk Matrix: Patch Installer (jackson-databind) — CVE-2020-9546
Oracle Oracle Global Lifecycle Management Risk Matrix: Patch Installer (jackson-databind) vulnerability
CVE: CVE-2020-9546
CVSS: 0.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2020 (JUL 2020)
Red Hat
jackson-databind: Serialization gadgets in shaded-hikari-config
vendor_redhat·2020-03-02·CVSS 9.8
CVE-2020-9546 [CRITICAL] CWE-502 jackson-databind: Serialization gadgets in shaded-hikari-config
jackson-databind: Serialization gadgets in shaded-hikari-config
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
A flaw was found in jackson-databind 2.x in versions prior to 2.9.10.4. FasterXML jackson-databind 2.x mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Red Hat OpenStack Platform ships OpenDaylight, which contains the vulnerable jackson-databind. However, OpenDaylight does not expose jackson-databind in a way that would make it vulnerable, lowering the impact of the vulner
Debian
CVE-2020-9546: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
vendor_debian·2020·CVSS 9.8
CVE-2020-9546 [CRITICAL] CVE-2020-9546: jackson-databind - FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
Scope: local
bookworm: resolved (fixed in 2.11.1-1)
bullseye: resolved (fixed in 2.11.1-1)
forky: resolved (fixed in 2.11.1-1)
sid: resolved (fixed in 2.11.1-1)
trixie: resolved (fixed in 2.11.1-1)
OSV
jackson-databind vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-11307 [CRITICAL] jackson-databind vulnerabilities
jackson-databind vulnerabilities
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,
CVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2
GHSA
jackson-databind mishandles the interaction between serialization gadgets and typing
ghsa·2020-04-23
CVE-2020-9546 [CRITICAL] CWE-502 jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
OSV
jackson-databind mishandles the interaction between serialization gadgets and typing
osv·2020-04-23
CVE-2020-9546 [CRITICAL] jackson-databind mishandles the interaction between serialization gadgets and typing
jackson-databind mishandles the interaction between serialization gadgets and typing
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
OSV
CVE-2020-9546: FasterXML jackson-databind 2
osv·2020-03-02·CVSS 9.8
CVE-2020-9546 [CRITICAL] CVE-2020-9546: FasterXML jackson-databind 2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-config
bugzilla·2020-03-23·CVSS 9.8
CVE-2020-9546 [CRITICAL] CVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-config
CVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-config
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
Upstream issue:
https://github.com/FasterXML/jackson-databind/issues/2631
Discussion:
Created jackson-databind tracking bugs for this issue:
Affects: fedora-all [bug 1816333]
---
This vulnerability is out of security support scope for the following products:
* Red Hat Jboss Fuse 6
* Red Hat JBoss A-MQ 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
Upstream fix:
https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c8
Bugzilla
CVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-config [fedora-all]
bugzilla·2020-03-23·CVSS 9.8
CVE-2020-9546 [CRITICAL] CVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-config [fedora-all]
CVE-2020-9546 jackson-databind: Serialization gadgets in shaded-hikari-config [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
arxiv_fulltext·2026-03
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
## Abstract
Open-source software supply chain security relies heavily on assessing affected versions of library vulnerabilities. While prior studies have leveraged exploits for verifying vulnerability affected versions, they point out a key limitation that exploits are version-specific and cannot be directly applied across library versions. Despite being widely acknowledged, this limitation has not been systematically validated at scale, leaving the actual applicability of exploits across versions unexplored. To fill this gap, we conduct the first large-scale empirical study on exploit applicability across library versions. We construct a comprehensive dataset consisting of 259 exploits spanning 128 Java libraries and 28,150 historical versions, covering 61 CWEs that account for 76.33% of
https://github.com/FasterXML/jackson-databind/issues/2631https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00008.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20200904-0006/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/FasterXML/jackson-databind/issues/2631https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00008.htmlhttps://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062https://security.netapp.com/advisory/ntap-20200904-0006/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-03-02
Published