CVE-2020-10968

Aliases:GHSA-rf6r-2c4q-2vwgDEBIAN-CVE-2020-10968CGA-3xmv-935c-ccpqCGA-5rrp-q97c-r2pwCGA-6cch-66x9-29p7CGA-8wc4-qrw8-rpcrCGA-8x3m-ccr3-992vCGA-9mxq-xh8j-p38wCGA-9pxr-66hq-xg3rCGA-c7mj-m3fc-72r2CGA-cqpx-qgr6-q27fCGA-pjvh-7rm6-jpqxCGA-qc8g-w628-hmw9CGA-rq58-xcph-pfmcCGA-rrvc-5p26-w9h9CGA-wq9h-mg25-p86vCGA-wrgg-jp43-3xj9CGA-4vmj-h37x-8m62CGA-897c-476h-w2hhCGA-8vcx-h6gg-jq49CGA-cfhp-97fm-w3g2CGA-f7v4-3h67-pvjcCGA-f95g-rjph-554gCGA-hpj4-6hmj-wm85CGA-wmrc-4934-54jwCGA-2hjx-4mjg-j42mCGA-423r-4597-mm45CGA-476j-q364-m8jmCGA-4qhj-fpcm-hw9rCGA-665x-f78p-xw4gCGA-6wc5-rxww-2292CGA-72fq-36wq-qm52CGA-7wjc-7jxj-6q6vCGA-8cjc-fq7c-526vCGA-9394-7rcx-f9jgCGA-c92g-w85c-37v4CGA-gxc8-pq6g-vgmpCGA-hrj6-r493-wqm8CGA-jjr5-v866-7m6mCGA-jqjv-c34p-wrpjCGA-m5h2-rv9g-5qphCGA-mfvc-fhf4-chmxCGA-ph23-jh5h-jqx7CGA-pv7q-h597-v325CGA-q5c9-6wc7-q9wjCGA-2mvf-mwwm-cxprCGA-3jg2-74r9-237fCGA-3qrx-2whv-cwhhCGA-5235-hrf5-8r3rCGA-676w-3vfv-839cCGA-84vq-99c5-ppw5CGA-8mcg-3q3x-94j9CGA-8whh-prr2-xwr7CGA-9jp6-x9rc-rjqgCGA-cw9v-rw69-859hCGA-gjhg-j6mx-3jmgCGA-j7pp-jghh-hhj2CGA-p8h3-x72m-cq38CGA-w7wc-v924-9g7j
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 26 Mar 2020, 12:43
Last modified:04 Aug 2024, 11:21

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
3.63% LOW
4% probability -0.40%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Mar 2020, 12:43
Published
Vulnerability first disclosed
04 Aug 2024, 11:21
Last Modified
Vulnerability information updated

Description

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 3.63% Percentile: 89%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • chainguardeco-java-gradle-4.10

    all

  • chainguardeco-java-gradle-4.10.1

    all

  • chainguardeco-java-gradle-4.10.2

    all

  • chainguardeco-java-gradle-4.10.3

    all

  • chainguardeco-java-gradle-4.9

    all

  • chainguardeco-java-gradle-5.0

    all

  • chainguardeco-java-gradle-5.1

    all

  • chainguardeco-java-gradle-5.1.1

    all

  • chainguardeco-java-gradle-5.2

    all

  • chainguardeco-java-gradle-5.2.1

    all

  • chainguardeco-java-gradle-5.3

    all

  • chainguardeco-java-gradle-5.3.1

    all

  • chainguardeco-java-gradle-5.4

    all

  • chainguardeco-java-gradle-5.4.1

    all

  • chainguardeco-java-gradle-5.5

    all

  • chainguardeco-java-gradle-5.5.1

    all

  • chainguardeco-java-gradle-5.6

    all

  • chainguardeco-java-gradle-5.6.1

    all

  • chainguardeco-java-gradle-5.6.2

    all

  • chainguardeco-java-gradle-5.6.3

    all

  • chainguardeco-java-gradle-5.6.4

    all

  • chainguardeco-java-gradle-6.0

    all

  • chainguardeco-java-gradle-6.0.1

    all

  • chainguardeco-java-gradle-6.1

    all

  • chainguardeco-java-gradle-6.1.1

    all

  • chainguardeco-java-gradle-6.2

    all

  • chainguardeco-java-gradle-6.2.1

    all

  • chainguardeco-java-gradle-6.2.2

    all

  • debianjackson-databind

    < 2.11.1-1 | < 2.11.1-1 | < 2.11.1-1 | < 2.11.1-1

  • debiandebian_linux

    8.0

  • fasterxmljackson-databind

    ≥ 2.9.0, < 2.9.10.4

  • com.fasterxml.jackson.corejackson-databind

    ≥ 2.9.0, < 2.9.10.4

  • netappsteelstore_cloud_integrated_storage

    na

  • oracleagile_plm

    9.3.6

  • oracleagile_product_lifecycle_management

    9.3.6

  • oracleautovue_for_agile_product_lifecycle_management

    21.0.2

  • oraclebanking_digital_experience

    18.1 | 18.2 | 18.3 | 19.1 | 19.2 | 20.1

  • oraclebanking_platform

    ≥ 2.4.0, ≤ 2.9.0

  • oraclecommunications_calendar_server

    8.0.0.4.0

  • oraclecommunications_contacts_server

    8.0.0.4.0 | 8.0.0.5.0

  • oraclecommunications_diameter_signaling_router

    ≥ 8.0.0, ≤ 8.2.2

  • oraclecommunications_element_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oraclecommunications_evolved_communications_application_server

    7.1

  • oraclecommunications_instant_messaging_server

    10.0.1.4.0

  • oraclecommunications_network_charging_and_control

    ≥ 12.0.0, ≤ 12.0.3 | 6.0.1

  • oraclecommunications_session_report_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oraclecommunications_session_route_manager

    ≥ 8.2.0, ≤ 8.2.2

  • oracleenterprise_manager_base_platform

    13.3.0.0 | 13.4.0.0

  • oraclefinancial_services_analytical_applications_infrastructure

    ≥ 8.0.6, ≤ 8.1.0

  • oraclefinancial_services_institutional_performance_analytics

    8.0.6 | 8.0.7 | 8.1.0

Showing first 50 affected entries in server-rendered view.

References (15)