CVE-2019-14540
critical · 9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
9.8
CVSS
10.8%
EPSS (exploit prob.)
96th
EPSS percentile
2019-09-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fasterxml | jackson-databind | >= 2.0.0, < 2.6.7.3 |
| fasterxml | jackson-databind | >= 2.7.0, < 2.8.11.5 |
| fasterxml | jackson-databind | >= 2.9.0, < 2.9.10 |
| netapp | oncommand_api_services | all versions |
| netapp | oncommand_workflow_automation | all versions |
| netapp | steelstore_cloud_integrated_storage | all versions |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| redhat | jboss_enterprise_application_platform | 7.2 |
| redhat | jboss_enterprise_application_platform | 7.3 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| oracle | banking_platform | 2.4.0 |
| oracle | banking_platform | 2.4.1 |
| oracle | banking_platform | 2.5.0 |
| oracle | banking_platform | 2.6.0 |
| oracle | banking_platform | 2.6.1 |
| oracle | banking_platform | 2.7.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | customer_management_and_segmentation_foundation | 18.0 |
| oracle | financial_services_analytical_applications_infrastructure | >= 8.0.2, <= 8.0.8 |
| oracle | global_lifecycle_management_opatch | < 11.2.0.3.23 |
| oracle | global_lifecycle_management_opatch | >= 12.2.0.1.0, < 12.2.0.1.19 |
| oracle | global_lifecycle_management_opatch | >= 13.9.4.0.0, < 13.9.4.2.1 |
| oracle | goldengate_application_adapters | 19.1.0.0.0 |
| oracle | goldengate_stream_analytics | < 19.1.0.0.1 |
| oracle | mysql | >= 5.7.0, <= 5.7.30 |
| oracle | mysql | >= 8.0.0, <= 8.0.20 |
| oracle | primavera_gateway | 15.2 |
| oracle | primavera_gateway | 15.2.18 |
| oracle | primavera_gateway | 16.2 |
| oracle | primavera_gateway | 16.2.11 |
| oracle | primavera_gateway | 17.12 |
| oracle | primavera_gateway | 17.12.6 |
| oracle | primavera_gateway | 18.8.0 |
| oracle | primavera_gateway | 18.8.8.1 |
Check a specific version with /api/v1/cve/match.
References
- https://access.redhat.com/errata/RHSA-2019:3200
- https://access.redhat.com/errata/RHSA-2020:0159
- https://access.redhat.com/errata/RHSA-2020:0160
- https://access.redhat.com/errata/RHSA-2020:0161
- https://access.redhat.com/errata/RHSA-2020:0164
- https://access.redhat.com/errata/RHSA-2020:0445
- https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x
- https://github.com/FasterXML/jackson-databind/issues/2410
- https://github.com/FasterXML/jackson-databind/issues/2449
- https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69%40%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb%40%3Ccommits.hbase.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-14540