← All CVEs

CVE-2018-14718

critical · 9.8

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

9.8
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2019-01-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
fasterxmljackson-databind>= 2.0.0, < 2.6.7.3
fasterxmljackson-databind>= 2.7.0, < 2.7.9.5
fasterxmljackson-databind>= 2.8.0, < 2.8.11.3
fasterxmljackson-databind>= 2.9.0, < 2.9.7
debiandebian_linux8.0
debiandebian_linux9.0
oraclebanking_platform2.5.0
oraclebanking_platform2.6.0
oraclebanking_platform2.6.1
oraclebanking_platform2.6.2
oraclebusiness_process_management_suite12.1.3.0.0
oraclebusiness_process_management_suite12.2.1.3.0
oraclecommunications_billing_and_revenue_management7.5
oraclecommunications_billing_and_revenue_management12.0
oraclecommunications_instant_messaging_server10.0.1.3.0
oracleenterprise_manager_for_virtualization13.2.2
oracleenterprise_manager_for_virtualization13.2.3
oracleenterprise_manager_for_virtualization13.3.1
oraclefinancial_services_analytical_applications_infrastructure8.0.2
oraclefinancial_services_analytical_applications_infrastructure8.0.3
oraclefinancial_services_analytical_applications_infrastructure8.0.4
oraclefinancial_services_analytical_applications_infrastructure8.0.5
oraclefinancial_services_analytical_applications_infrastructure8.0.6
oraclefinancial_services_analytical_applications_infrastructure8.0.7
oracleglobal_lifecycle_management_opatch< 11.2.0.3.23
oracleglobal_lifecycle_management_opatch>= 12.2.0.1.0, < 12.2.0.1.19
oracleglobal_lifecycle_management_opatch>= 13.9.4.0.0, < 13.9.4.2.1
oraclejd_edwards_enterpriseone_orchestrator9.2
oraclejd_edwards_enterpriseone_tools9.2
oraclejdeveloper12.1.3.0.0
oraclejdeveloper12.2.1.3.0
oraclenosql_database< 19.3.12
oraclenosql_database19.3.12
oracleprimavera_p6_enterprise_project_portfolio_management>= 17.7, <= 17.12
oracleprimavera_p6_enterprise_project_portfolio_management15.1
oracleprimavera_p6_enterprise_project_portfolio_management15.2
oracleprimavera_p6_enterprise_project_portfolio_management16.1
oracleprimavera_p6_enterprise_project_portfolio_management16.2
oracleprimavera_p6_enterprise_project_portfolio_management18.8
oracleprimavera_unifier>= 17.7, <= 17.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-14718