CVE-2019-17267

Aliases:GHSA-f3j5-rmmp-3fc5
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 06 Oct 2019, 23:08
Last modified:05 Aug 2024, 01:33

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
1.23% LOW
1% probability +0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Oct 2019, 23:08
Published
Vulnerability first disclosed
05 Aug 2024, 01:33
Last Modified
Vulnerability information updated

Description

A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 1.23% Percentile: 79%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • debiandebian_linux

    8.0

  • fasterxmljackson-databind

    ≥ 2.0.0, < 2.8.11.5 | ≥ 2.9.0, < 2.9.10

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.9.0, < 2.9.10 | < 2.8.11.5

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netapponcommand_api_services

    na

  • netapponcommand_workflow_automation

    na

  • netappservice_level_manager

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • oraclecustomer_management_and_segmentation_foundation

    < 18.0

  • oraclegoldengate_application_adapters

    19.1.0.0.0

  • oracleretail_customer_management_and_segmentation_foundation

    17.0

  • UnknownWebLogic Server

    12.2.1.3.0

  • redhatjboss_enterprise_application_platform

    7.2 | 7.3

References (31)