Total vulnerabilities in the database
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
Software | From | Fixed in |
---|---|---|
fasterxml / jackson-databind | 2.9.0 | 2.9.10 |
redhat / jboss_enterprise_application_platform | 7.0 | 7.0.x |
redhat / decision_manager | 7.0 | 7.0.x |
redhat / jboss_fuse | 7.0.0 | 7.0.0.x |
redhat / process_automation | 7.0 | 7.0.x |
redhat / jboss_data_grid | 7.0.0 | 7.0.0.x |
redhat / openshift_container_platform | 4.3 | 4.3.x |
apache / geode | 1.12.0 | 1.12.0.x |
![]() |
- | 2.6.7.3 |
![]() |
2.8.0 | 2.8.11.5 |
![]() |
2.9.0 | 2.9.10 |
fasterxml / jackson-databind | 2.0.0 | 2.6.7.3 |
fasterxml / jackson-databind | 2.7.0 | 2.8.11.5 |