CVE-2019-10202

Aliases:GHSA-c27h-mcmw-48hv
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 01 Oct 2019, 14:22
Last modified:04 Aug 2024, 22:17

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
7.42% LOW
7% probability +0.18%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Oct 2019, 14:22
Published
Vulnerability first disclosed
04 Aug 2024, 22:17
Last Modified
Vulnerability information updated

Description

A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 7.42% Percentile: 92%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • org.codehaus.jacksonjackson-mapper-asl

    ≤ 1.9.13

  • redhatcodehaus

    Codehaus 1.9.x

  • redhatjboss_enterprise_application_platform

    7.2.0

References (18)