296,733
Total vulnerabilities in the database
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
| Software | From | Fixed in |
|---|---|---|
| fasterxml / jackson-databind | 2.9.0 | 2.9.10 |
| redhat / jboss_enterprise_application_platform | 7.0 | 7.0.x |
| redhat / decision_manager | 7.0 | 7.0.x |
| redhat / jboss_fuse | 7.0.0 | 7.0.0.x |
| redhat / process_automation | 7.0 | 7.0.x |
| redhat / jboss_data_grid | 7.0.0 | 7.0.0.x |
| redhat / openshift_container_platform | 4.3 | 4.3.x |
| apache / geode | 1.12.0 | 1.12.0.x |
com.fasterxml.jackson.core / jackson-databind
|
- | 2.6.7.3 |
com.fasterxml.jackson.core / jackson-databind
|
2.8.0 | 2.8.11.5 |
com.fasterxml.jackson.core / jackson-databind
|
2.9.0 | 2.9.10 |
| fasterxml / jackson-databind | 2.0.0 | 2.6.7.3 |
| fasterxml / jackson-databind | 2.7.0 | 2.8.11.5 |