← All CVEs

CVE-2019-14439

high · 7.5

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

7.5
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2019-07-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
fasterxmljackson-databind>= 2.0.0, < 2.6.7.3
fasterxmljackson-databind>= 2.7.0, < 2.7.9.6
fasterxmljackson-databind>= 2.8.0, < 2.8.11.4
fasterxmljackson-databind>= 2.9.0, < 2.9.9.2
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0
fedoraprojectfedora29
fedoraprojectfedora30
apachedrill1.16.0
redhatjboss_middleware_text-only_advisories1.0
oraclebanking_platform2.4.0
oraclebanking_platform2.4.1
oraclebanking_platform2.5.0
oraclebanking_platform2.6.0
oraclebanking_platform2.6.1
oraclebanking_platform2.7.0
oraclebanking_platform2.7.1
oraclecommunications_diameter_signaling_router8.0.0
oraclecommunications_diameter_signaling_router8.1
oraclecommunications_diameter_signaling_router8.2
oraclecommunications_diameter_signaling_router8.2.1
oraclecommunications_instant_messaging_server10.0.1.3.0
oraclefinancial_services_analytical_applications_infrastructure>= 8.0.2, <= 8.0.8
oracleglobal_lifecycle_management_opatch< 11.2.0.3.23
oracleglobal_lifecycle_management_opatch>= 12.2.0.1.0, < 12.2.0.1.19
oracleglobal_lifecycle_management_opatch>= 13.9.4.0.0, < 13.9.4.2.1
oracleglobal_lifecycle_management_opatch11.2.0.3.23
oracleglobal_lifecycle_management_opatch13.9.4.2.1
oraclegoldengate_stream_analytics< 19.1.0.0.1
oraclejd_edwards_enterpriseone_orchestrator9.2
oraclejd_edwards_enterpriseone_tools9.2
oracleprimavera_gateway>= 17.7, <= 17.12
oracleprimavera_gateway15.2
oracleprimavera_gateway16.1
oracleprimavera_gateway16.2
oracleprimavera_gateway18.8.0
oracleretail_customer_management_and_segmentation_foundation17.0
oracleretail_xstore_point_of_service7.1
oracleretail_xstore_point_of_service15.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-14439