cbcvebase.

Oracle Global Lifecycle Management Opatch vulnerabilities

25 known vulnerabilities affecting oracle/global_lifecycle_management_opatch.

Total CVEs
25
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH12MEDIUM3

Vulnerabilities

Page 1 of 2
CVE-2020-9547P1CRITICALCVSS 9.8ExploitedPoCfixed in 12.2.0.1.202020-03-02
CVE-2020-9547 [CRITICAL] CWE-502 CVE-2020-9547: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
nvd
CVE-2020-9548P1CRITICALCVSS 9.8ExploitedPoCfixed in 12.2.0.1.202020-03-02
CVE-2020-9548 [CRITICAL] CWE-502 CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
nvd
CVE-2018-14718P2CRITICALCVSS 9.8fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2019-01-02
CVE-2018-14718 [CRITICAL] CWE-502 CVE-2018-14718: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
nvd
CVE-2018-14719P2CRITICALCVSS 9.8fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2020-8840P3CRITICALCVSS 9.8fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2020-02-10
CVE-2020-8840 [CRITICAL] CWE-502 CVE-2020-8840: FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demo FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
nvd
CVE-2019-14540P3CRITICALCVSS 9.8fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2019-09-15
CVE-2019-14540 [CRITICAL] CWE-502 CVE-2019-14540: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
nvd
CVE-2019-20330P3CRITICALCVSS 9.8fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2020-01-03
CVE-2019-20330 [CRITICAL] CWE-502 CVE-2019-20330: FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
nvd
CVE-2018-11307P3CRITICALCVSS 9.8fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2019-07-09
CVE-2018-11307 [CRITICAL] CWE-502 CVE-2018-11307: An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default ty An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
nvd
CVE-2019-16335P3CRITICALCVSS 9.8fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2019-09-15
CVE-2019-16335 [CRITICAL] CVE-2019-16335: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
nvd
CVE-2018-1320P3HIGHCVSS 7.5fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+1 more2019-01-07
CVE-2018-1320 [HIGH] CWE-295 CVE-2018-1320: Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComple Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
nvd
CVE-2019-14439P3HIGHCVSS 7.5fixed in 11.2.0.3.23≥ 12.2.0.1.0, < 12.2.0.1.19+3 more2019-07-30
CVE-2019-14439 [HIGH] CWE-502 CVE-2019-14439: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occ A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
nvd
CVE-2020-10673P3HIGHCVSS 8.8fixed in 12.2.0.1.202020-03-18
CVE-2020-10673 [HIGH] CWE-502 CVE-2020-10673: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
nvd
CVE-2020-9546P3CRITICALCVSS 9.8fixed in 12.2.0.1.202020-03-02
CVE-2020-9546 [CRITICAL] CWE-502 CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
nvd
CVE-2020-11620P3HIGHCVSS 8.1fixed in 12.2.0.1.202020-04-07
CVE-2020-11620 [HIGH] CWE-502 CVE-2020-11620: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
nvd
CVE-2020-11113P3HIGHCVSS 8.8fixed in 12.2.0.1.202020-03-31
CVE-2020-11113 [HIGH] CWE-502 CVE-2020-11113: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
nvd
CVE-2020-10969P3HIGHCVSS 8.8fixed in 12.2.0.1.202020-03-26
CVE-2020-10969 [HIGH] CWE-502 CVE-2020-10969: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
nvd
CVE-2020-11112P3HIGHCVSS 8.8fixed in 12.2.0.1.202020-03-31
CVE-2020-11112 [HIGH] CWE-502 CVE-2020-11112: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
nvd
CVE-2020-10672P3HIGHCVSS 8.8fixed in 12.2.0.1.202020-03-18
CVE-2020-10672 [HIGH] CWE-502 CVE-2020-10672: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
nvd
CVE-2020-11619P3HIGHCVSS 8.1fixed in 12.2.0.1.202020-04-07
CVE-2020-11619 [HIGH] CWE-502 CVE-2020-11619: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
nvd
CVE-2020-10968P3HIGHCVSS 8.8fixed in 12.2.0.1.202020-03-26
CVE-2020-10968 [HIGH] CWE-502 CVE-2020-10968: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
nvd
Oracle Global Lifecycle Management Opatch vulnerabilities | cvebase