CVE-2017-7525
critical · 9.8A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
9.8
CVSS
37.7%
EPSS (exploit prob.)
98th
EPSS percentile
2018-02-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-184CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fasterxml | jackson-databind | < 2.6.7.1 |
| fasterxml | jackson-databind | >= 2.7.0, < 2.7.9.1 |
| fasterxml | jackson-databind | >= 2.8.0, < 2.8.9 |
| fasterxml | jackson-databind | 2.9.0 |
| fasterxml | jackson-databind | 2.9.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| netapp | oncommand_balance | all versions |
| netapp | oncommand_performance_manager | all versions |
| netapp | oncommand_performance_manager | all versions |
| netapp | oncommand_shift | all versions |
| netapp | snapcenter | all versions |
| redhat | openshift_container_platform | 4.1 |
| redhat | virtualization | 4.0 |
| redhat | virtualization_host | 4.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | jboss_enterprise_application_platform | 6.0.0 |
| redhat | jboss_enterprise_application_platform | 6.4.0 |
| redhat | jboss_enterprise_application_platform | 7.0 |
| redhat | jboss_enterprise_application_platform | 7.1 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | jboss_enterprise_application_platform | 6.0.0 |
| redhat | jboss_enterprise_application_platform | 6.4.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | openshift_container_platform | 3.11 |
| oracle | banking_platform | 2.5.0 |
| oracle | banking_platform | 2.6.0 |
| oracle | banking_platform | 2.6.1 |
| oracle | banking_platform | 2.6.2 |
| oracle | communications_billing_and_revenue_management | 7.5 |
| oracle | communications_billing_and_revenue_management | 12.0 |
| oracle | communications_communications_policy_management | >= 12.0, <= 12.5.2 |
| oracle | communications_diameter_signaling_route | < 8.3 |
| oracle | communications_instant_messaging_server | 10.0.1 |
| oracle | communications_instant_messaging_server | 10.0.1.2.0 |
| oracle | enterprise_manager_for_virtualization | 13.2.2 |
| oracle | enterprise_manager_for_virtualization | 13.2.3 |
| oracle | enterprise_manager_for_virtualization | 13.3.1 |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.2.0.0 |
Check a specific version with /api/v1/cve/match.
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/99623
- http://www.securitytracker.com/id/1039744
- http://www.securitytracker.com/id/1039947
- http://www.securitytracker.com/id/1040360
- https://access.redhat.com/errata/RHSA-2017:1834
- https://access.redhat.com/errata/RHSA-2017:1835
- https://access.redhat.com/errata/RHSA-2017:1836
- https://access.redhat.com/errata/RHSA-2017:1837
- https://access.redhat.com/errata/RHSA-2017:1839
- https://access.redhat.com/errata/RHSA-2017:1840
- https://access.redhat.com/errata/RHSA-2017:2477
- https://access.redhat.com/errata/RHSA-2017:2546
- https://access.redhat.com/errata/RHSA-2017:2547
- https://access.redhat.com/errata/RHSA-2017:2633
- https://access.redhat.com/errata/RHSA-2017:2635
- https://access.redhat.com/errata/RHSA-2017:2636
- https://access.redhat.com/errata/RHSA-2017:2637
- https://access.redhat.com/errata/RHSA-2017:2638
- https://access.redhat.com/errata/RHSA-2017:3141
- https://access.redhat.com/errata/RHSA-2017:3454
- https://access.redhat.com/errata/RHSA-2017:3455
- https://access.redhat.com/errata/RHSA-2017:3456
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-7525