CVE-2019-16942

Aliases:GHSA-mx7p-6679-8g3q
Advisory lineage Upstream: 0 Downstream: 10
Modified
Published: 01 Oct 2019, 16:04
Last modified:05 Aug 2024, 01:24

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
0.43% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Oct 2019, 16:04
Published
Vulnerability first disclosed
05 Aug 2024, 01:24
Last Modified
Vulnerability information updated

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.43% Percentile: 63%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • fasterxmljackson-databind

    ≥ 2.0.0, < 2.6.7.3 | ≥ 2.8.0, < 2.8.11.5 | ≥ 2.9.0, < 2.9.10.1

  • fedoraprojectfedora

    30 | 31

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.9.0, < 2.9.10.1 | ≥ 2.7.0, < 2.8.11.5 | ≥ 2.0.0, < 2.6.7.3

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netapponcommand_api_services

    na

  • netapponcommand_workflow_automation

    na

  • netappservice_level_manager

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • oraclebanking_platform

    2.4.0 | 2.4.1 | 2.5.0 | 2.6.0 | 2.6.1 | 2.6.2 | 2.7.0 | 2.7.1 | 2.9.0

  • oraclecommunications_billing_and_revenue_management

    7.5.0.23.0 | 12.0.0.3.0

  • oraclecommunications_calendar_server

    8.0.0.2.0 | 8.0.0.3.0

  • oraclecommunications_cloud_native_core_network_slice_selection_function

    1.2.1

  • oraclecommunications_evolved_communications_application_server

    7.1

  • oracledatabase_server

    12.2.0.1 | 18c | 19c

  • oracleglobal_lifecycle_management_nextgen_oui_framework

    12.2.1.3.0 | 12.2.1.4.0 | 13.9.4.2.2

  • oraclegoldengate_application_adapters

    19.1.0.0.0

  • oraclejd_edwards_enterpriseone_orchestrator

    9.2

  • oraclejd_edwards_enterpriseone_tools

    9.2

  • oracleprimavera_gateway

    ≥ 17.12.0, ≤ 17.12.6 | ≥ 18.8.0, ≤ 18.8.8 | 19.12.0

  • oracleprimavera_unifier

    ≥ 17.7, ≤ 17.12 | 16.1 | 16.2 | 18.8 | 19.12

  • oracleretail_merchandising_system

    15.0.3 | 16.0.2 | 16.0.3

  • oracleretail_sales_audit

    14.1

  • oraclesiebel_engineering_-_installer_\&_deployment

    ≤ 2.20.5

  • oraclesiebel_ui_framework

    ≤ 20.5 | 20.6

  • oraclewebcenter_portal

    12.2.1.3.0 | 12.2.1.4.0

  • oraclewebcenter_sites

    12.2.1.3.0 | 12.2.1.4.0

  • UnknownWebLogic Server

    12.2.1.3.0 | 12.2.1.4.0

  • redhatjboss_enterprise_application_platform

    7.2.0 | 7.3

References (47)