← All CVEs

CVE-2017-17485

critical · 9.8

FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.

9.8
CVSS
49.7%
EPSS (exploit prob.)
99th
EPSS percentile
2018-01-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
fasterxmljackson-databind< 2.6.7.3
fasterxmljackson-databind>= 2.7.0, < 2.7.9.2
fasterxmljackson-databind>= 2.8.0, < 2.8.11
fasterxmljackson-databind>= 2.9.0, < 2.9.4
debiandebian_linux8.0
debiandebian_linux9.0
redhatjboss_enterprise_application_platform6.0.0
redhatjboss_enterprise_application_platform6.4.0
redhatjboss_enterprise_application_platform7.1
redhatenterprise_linux_server6.0
redhatenterprise_linux_server7.0
redhatjboss_enterprise_application_platform6.0.0
redhatjboss_enterprise_application_platform6.4.0
redhatenterprise_linux_server5.0
redhatopenshift_container_platform4.1
redhatenterprise_linux_server7.0
redhatopenshift_container_platform3.11
netappe-series_santricity_os_controller>= 11.0.0, <= 11.60.3
netappe-series_santricity_web_services_proxyall versions
netapponcommand_shiftall versions
netappsnapcenterall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-17485