← All CVEs

CVE-2018-14721

critical · 10

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

10
CVSS
10.5%
EPSS (exploit prob.)
96th
EPSS percentile
2019-01-02
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-918

Affected products

VendorProductAffected versions
fasterxmljackson-databind>= 2.6.0, < 2.6.7.2
fasterxmljackson-databind>= 2.7.0, < 2.7.9.5
fasterxmljackson-databind>= 2.8.0, < 2.8.11.3
fasterxmljackson-databind>= 2.9.0, < 2.9.7
fasterxmljackson-databind2.7.0
fasterxmljackson-databind2.7.0
fasterxmljackson-databind2.7.0
fasterxmljackson-databind2.8.0
fasterxmljackson-databind2.8.0
fasterxmljackson-databind2.9.0
fasterxmljackson-databind2.9.0
fasterxmljackson-databind2.9.0
fasterxmljackson-databind2.9.0
debiandebian_linux8.0
debiandebian_linux9.0
oraclebanking_platform2.5.0
oraclebanking_platform2.6.0
oraclebanking_platform2.6.1
oraclebanking_platform2.6.2
oraclecommunications_billing_and_revenue_management7.5
oraclecommunications_billing_and_revenue_management12.0
oracleenterprise_manager_for_virtualization13.2.2
oracleenterprise_manager_for_virtualization13.2.3
oracleenterprise_manager_for_virtualization13.3.1
oraclefinancial_services_analytical_applications_infrastructure8.0.2
oraclefinancial_services_analytical_applications_infrastructure8.0.3
oraclefinancial_services_analytical_applications_infrastructure8.0.4
oraclefinancial_services_analytical_applications_infrastructure8.0.5
oraclefinancial_services_analytical_applications_infrastructure8.0.6
oraclefinancial_services_analytical_applications_infrastructure8.0.7
oraclejdeveloper12.1.3.0.0
oraclejdeveloper12.2.1.3.0
oracleprimavera_unifier>= 17.1, <= 17.12
oracleprimavera_unifier16.1
oracleprimavera_unifier16.2
oracleprimavera_unifier18.8
oracleretail_merchandising_system15.0
oracleretail_merchandising_system16.0
oraclewebcenter_portal12.2.1.3.0
redhatjboss_enterprise_application_platform7.2.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-14721