Total vulnerabilities in the database
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
Software | From | Fixed in |
---|---|---|
fasterxml / jackson-databind | 2.9.0 | 2.9.10.5 |
netapp / active_iq_unified_manager | 7.3 | 7.3.x |
netapp / active_iq_unified_manager | 9.5 | 9.5.x |
oracle / agile_plm | 9.3.6 | 9.3.6.x |
oracle / banking_digital_experience | 18.2 | 18.2.x |
oracle / banking_digital_experience | 18.3 | 18.3.x |
oracle / banking_digital_experience | 19.1 | 19.1.x |
oracle / banking_digital_experience | 18.1 | 18.1.x |
oracle / communications_diameter_signaling_router | 8.0.0 | 8.2.2.x |
oracle / banking_digital_experience | 19.2 | 19.2.x |
oracle / banking_digital_experience | 20.1 | 20.1.x |
oracle / communications_evolved_communications_application_server | 7.1 | 7.1.x |
oracle / communications_contacts_server | 8.0.0.5.0 | 8.0.0.5.0.x |
oracle / communications_calendar_server | 8.0.0.4.0 | 8.0.0.4.0.x |
oracle / communications_session_route_manager | 8.2.0 | 8.2.2.x |
oracle / communications_session_report_manager | 8.2.0 | 8.2.2.x |
oracle / communications_element_manager | 8.2.0 | 8.2.2.x |
![]() |
2.9.0 | 2.9.10.5 |