CVE-2018-7489

Aliases:GHSA-cggj-fvv3-cqwv
Advisory lineage Upstream: 0 Downstream: 11
Modified
Published: 26 Feb 2018, 15:00
Last modified:05 Aug 2024, 06:31

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.0 (nvd)
EPSS Score
36.21% HIGH
36% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Feb 2018, 15:00
Published
Vulnerability first disclosed
05 Aug 2024, 06:31
Last Modified
Vulnerability information updated

Description

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

CVSS Metrics

  • v3.0CRITICALScore: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 36.21% Percentile: 97%

Techniques & Countermeasures

  • CWE-184Incomplete List of Disallowed Inputs

    The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • debiandebian_linux

    8.0 | 9.0

  • fasterxmljackson-databind

    < 2.7.9.3 | ≥ 2.8.0, < 2.8.11.1 | ≥ 2.9.0, < 2.9.5

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.8.0, < 2.8.11.1 | ≥ 2.9.0, < 2.9.5 | ≥ 2.7.0, < 2.7.9.3 | < 2.6.7.5

  • oraclecommunications_billing_and_revenue_management

    7.5 | 12.0

  • oraclecommunications_instant_messaging_server

    10.0.1

  • redhatjboss_enterprise_application_platform

    6.4.19 | 7.1.2

References (38)