CVE-2019-14439

Aliases:GHSA-gwp4-hfv6-p7hw
Modified
Published: 30 Jul 2019, 10:49
Last modified:05 Aug 2024, 00:19

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
10.39% MEDIUM
10% probability +0.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2019, 10:49
Published
Vulnerability first disclosed
05 Aug 2024, 00:19
Last Modified
Vulnerability information updated

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 10.39% Percentile: 93%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • apachedrill

    1.16.0

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • fasterxmljackson-databind

    ≥ 2.0.0, < 2.6.7.3 | ≥ 2.7.0, < 2.7.9.6 | ≥ 2.8.0, < 2.8.11.4 | ≥ 2.9.0, < 2.9.9.2

  • fedoraprojectfedora

    29 | 30

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.9.0, < 2.9.9.2 | ≥ 2.8.0, < 2.8.11.4 | ≥ 2.7.0, < 2.7.9.6 | < 2.6.7.3

  • oraclebanking_platform

    2.4.0 | 2.4.1 | 2.5.0 | 2.6.0 | 2.6.1 | 2.7.0 | 2.7.1

  • oraclecommunications_diameter_signaling_router

    8.0.0 | 8.1 | 8.2 | 8.2.1

  • oraclecommunications_instant_messaging_server

    10.0.1.3.0

  • oraclefinancial_services_analytical_applications_infrastructure

    ≥ 8.0.2, ≤ 8.0.8

  • oracleglobal_lifecycle_management_opatch

    < 11.2.0.3.23 | ≥ 12.2.0.1.0, < 12.2.0.1.19 | ≥ 13.9.4.0.0, < 13.9.4.2.1 | 11.2.0.3.23 | 13.9.4.2.1

  • oraclegoldengate_stream_analytics

    < 19.1.0.0.1

  • oraclejd_edwards_enterpriseone_orchestrator

    9.2

  • oraclejd_edwards_enterpriseone_tools

    9.2

  • oracleprimavera_gateway

    ≥ 17.7, ≤ 17.12 | 15.2 | 16.1 | 16.2 | 18.8.0

  • oracleretail_customer_management_and_segmentation_foundation

    17.0

  • oracleretail_xstore_point_of_service

    7.1 | 15.0 | 16.0 | 17.0 | 18.0

  • oraclesiebel_engineering_-_installer_\&_deployment

    ≤ 19.8

  • oraclesiebel_ui_framework

    ≤ 19.10

  • redhatjboss_middleware_text-only_advisories

    1.0

References (49)