Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2019-14379

SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software From Fixed in
fasterxml / jackson-databind 2.9.0 2.9.9.2
fasterxml / jackson-databind 2.7.0 2.7.9.6
fasterxml / jackson-databind 2.8.0 2.8.11.4
debian / debian_linux 8.0 8.0.x
netapp / active_iq_unified_manager 7.3 7.3.x
netapp / active_iq_unified_manager 9.5 9.5.x
fedoraproject / fedora 29 29.x
fedoraproject / fedora 30 30.x
fedoraproject / fedora 31 31.x
redhat / jboss_enterprise_application_platform 7.2 7.2.x
redhat / jboss_enterprise_application_platform 7.3 7.3.x
redhat / openshift_container_platform 4.1 4.1.x
redhat / single_sign-on 7.3 7.3.x
redhat / openshift_container_platform 3.11 3.11.x
oracle / retail_xstore_point_of_service 15.0 15.0.x
oracle / primavera_unifier 16.2 16.2.x
oracle / banking_platform 2.4.0 2.4.0.x
oracle / retail_xstore_point_of_service 7.1 7.1.x
oracle / jd_edwards_enterpriseone_tools 9.2 9.2.x
oracle / banking_platform 2.4.1 2.4.1.x
oracle / primavera_gateway 16.2 16.2.x
oracle / primavera_gateway 15.2 15.2.x
oracle / banking_platform 2.5.0 2.5.0.x
oracle / primavera_unifier 16.1 16.1.x
oracle / retail_xstore_point_of_service 16.0 16.0.x
oracle / primavera_gateway 17.12 17.12.x
oracle / jd_edwards_enterpriseone_orchestrator 9.2 9.2.x
oracle / banking_platform 2.6.0 2.6.0.x
oracle / banking_platform 2.6.1 2.6.1.x
oracle / primavera_unifier 18.8 18.8.x
oracle / retail_customer_management_and_segmentation_foundation 17.0 17.0.x
oracle / primavera_unifier 17.7 17.12.x
oracle / siebel_ui_framework - 19.10.x
oracle / retail_xstore_point_of_service 17.0 17.0.x
oracle / retail_xstore_point_of_service 18.0 18.0.x
oracle / banking_platform 2.7.0 2.7.0.x
oracle / banking_platform 2.7.1 2.7.1.x
oracle / goldengate_stream_analytics - 19.1.0.0.1
oracle / communications_diameter_signaling_router 8.2.1 8.2.1.x
oracle / communications_diameter_signaling_router 8.0.0 8.0.0.x
oracle / communications_diameter_signaling_router 8.1 8.1.x
oracle / communications_diameter_signaling_router 8.2 8.2.x
oracle / financial_services_analytical_applications_infrastructure 8.0.2 8.0.8.x
oracle / primavera_gateway 18.8.0 18.8.0.x
oracle / siebel_engineering_-_installer_&_deployment - 19.8.x
oracle / communications_instant_messaging_server 10.0.1.3.0 10.0.1.3.0.x
apple / xcode - 13.3
com.fasterxml.jackson.core / jackson-databind - 2.9.9.2
fasterxml / jackson-databind 2.0.0 2.6.7.3