← All CVEs

CVE-2020-36179

high · 8.1

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.

8.1
CVSS
21.0%
EPSS (exploit prob.)
97th
EPSS percentile
2021-01-07
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
netappcloud_backupall versions
netappservice_level_managerall versions
debiandebian_linux9.0
oracleagile_product_lifecycle_management9.3.6
oracleapplication_testing_suite13.3.0.1
oracleautovue_for_agile_product_lifecycle_management21.0.2
oraclebanking_corporate_lending_process_management14.2
oraclebanking_corporate_lending_process_management14.3
oraclebanking_corporate_lending_process_management14.5
oraclebanking_credit_facilities_process_management14.2
oraclebanking_credit_facilities_process_management14.3
oraclebanking_credit_facilities_process_management14.5
oraclebanking_supply_chain_finance14.2
oraclebanking_supply_chain_finance14.3
oraclebanking_supply_chain_finance14.5
oraclebanking_treasury_management14.4
oraclebanking_virtual_account_management14.2.0
oraclebanking_virtual_account_management14.3.0
oraclebanking_virtual_account_management14.5.0
oracleblockchain_platform<= 21.1.2
oraclecommerce_platform>= 11.3.0, <= 11.3.2
oraclecommerce_platform11.2.0
oraclecommunications_billing_and_revenue_management7.5.0.23.0
oraclecommunications_billing_and_revenue_management12.0.0.3.0
oraclecommunications_cloud_native_core_policy1.14.0
oraclecommunications_cloud_native_core_unified_data_repository1.4.0
oraclecommunications_convergent_charging_controller12.0.4.0.0
oraclecommunications_diameter_signaling_route>= 8.0.0.0, <= 8.5.0.0
oraclecommunications_element_manager>= 8.2.0.0, <= 8.2.4.0
oraclecommunications_evolved_communications_application_server7.1
oraclecommunications_instant_messaging_server10.0.1.5.0
oraclecommunications_network_charging_and_control12.0.4.0.0
oraclecommunications_offline_mediation_controller12.0.0.3
oraclecommunications_policy_management12.5.0
oraclecommunications_pricing_design_center12.0.0.4.0
oraclecommunications_services_gatekeeper7.0
oraclecommunications_session_report_manager>= 8.0.0.0, <= 8.2.2.1
oraclecommunications_session_route_manager>= 8.2.0, <= 8.2.2.1
oraclecommunications_unified_inventory_management7.4.1
oracledata_integrator12.2.1.4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-36179