CVE-2020-36518
Vulnerability Summary
Timeline
Description
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.49%• Percentile: 66%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- debian•debian_linux
9.0 | 10.0 | 11.0
- fasterxml•jackson-databind
< 2.12.6.1 | ≥ 2.13.0, < 2.13.2.1
- com.fasterxml.jackson.core•jackson-databind
≥ 2.13.0, < 2.13.2.1 | < 2.12.6.1
- netapp•active_iq_unified_manager
na
- netapp•cloud_insights_acquisition_unit
na
- netapp•oncommand_insight
na
- netapp•oncommand_workflow_automation
na
- netapp•snap_creator_framework
na
- oracle•big_data_spatial_and_graph
< 23.1
- oracle•coherence
14.1.1.0.0
- oracle•commerce_platform
11.3.0 | 11.3.1 | 11.3.2
- oracle•communications_billing_and_revenue_management
≥ 12.0.0.4.0, ≤ 12.0.0.6.0
- oracle•communications_cloud_native_core_binding_support_function
22.1.3
- oracle•communications_cloud_native_core_console
1.9.0
- oracle•communications_cloud_native_core_network_repository_function
22.1.2 | 22.2.0
- oracle•communications_cloud_native_core_network_slice_selection_function
22.1.0 | 22.1.1
- oracle•communications_cloud_native_core_security_edge_protection_proxy
22.1.1
- oracle•communications_cloud_native_core_service_communication_proxy
22.2.0
- oracle•communications_cloud_native_core_unified_data_repository
22.2.0
- oracle•financial_services_analytical_applications_infrastructure
≥ 8.0.7, ≤ 8.1.0.0 | 8.1.1.0 | 8.1.2.0 | 8.1.2.1
- oracle•financial_services_behavior_detection_platform
≥ 8.1.1.0, ≤ 8.1.2.1 | 8.0.7.0.0 | 8.0.8
- oracle•financial_services_crime_and_compliance_management_studio
8.0.8.2.0 | 8.0.8.3.0
- oracle•financial_services_enterprise_case_management
≥ 8.1.1.0, ≤ 8.1.2.1 | 8.0.7.1 | 8.0.7.2 | 8.0.8.0 | 8.0.8.1
- oracle•financial_services_trade-based_anti_money_laundering
8.0.7 | 8.0.8
- oracle•global_lifecycle_management_nextgen_oui_framework
< 13.9.4.2.2 | 13.9.4.2.2
- oracle•global_lifecycle_management_opatch
< 12.2.0.1.30
- oracle•graph_server_and_client
< 22.2.0
- oracle•health_sciences_empirica_signal
9.1.0.5.2
- oracle•peoplesoft_enterprise_peopletools
8.58 | 8.59
- oracle•primavera_gateway
≥ 17.12.0, ≤ 17.12.11 | ≥ 18.8.0, ≤ 18.8.14 | ≥ 19.12.0, ≤ 19.12.13 | ≥ 20.12.0, ≤ 20.12.18 | ≥ 21.12.0, ≤ 21.12.1
- oracle•primavera_p6_enterprise_project_portfolio_management
≥ 17.12.0.0, ≤ 17.12.20.4 | ≥ 18.8.0.0, ≤ 18.8.25.4 | ≥ 19.12.0, ≤ 19.12.19.0 | ≥ 20.12.0.0, ≤ 21.12.4.0
- oracle•primavera_unifier
≥ 17.0, ≤ 17.12 | 18.0 | 19.12 | 20.12 | 21.12
- oracle•retail_sales_audit
15.0.3.1
- oracle•sd-wan_edge
9.0 | 9.1
- oracle•spatial_studio
< 20.1.0
- oracle•utilities_framework
4.3.0.5.0 | 4.3.0.6.0 | 4.4.0.0.0 | 4.4.0.2.0 | 4.4.0.3.0 | 4.4.0.5.0
- Unknown•WebLogic Server
12.2.1.3.0 | 12.2.1.4.0 | 14.1.1.0.0
References (17)
- https://github.com/FasterXML/jackson-databind/issues/2816
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.netapp.com/advisory/ntap-20220506-0004/
- https://www.debian.org/security/2022/dsa-5283
- https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html
- https://nvd.nist.gov/vuln/detail/CVE-2020-36518
- https://github.com/FasterXML/jackson-databind/commit/0a8157c6ca478b1bc7be4ba7dccdb3863275f0de
- https://github.com/FasterXML/jackson-databind/commit/3cc52f82ecf943e06c1d7c3b078e405fb3923d2b
- https://github.com/FasterXML/jackson-databind/commit/8238ab41d0350fb915797c89d46777b4496b74fd
- https://github.com/FasterXML/jackson-databind/commit/b3587924ee5d8695942f364d0d404d48d0ea6126
- https://github.com/FasterXML/jackson-databind/commit/fcfc4998ec23f0b1f7f8a9521c2b317b6c25892b
- https://github.com/FasterXML/jackson-databind
- https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12
- https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13
- https://security.netapp.com/advisory/ntap-20220506-0004