CVE-2018-1000873
20.12.2018, 17:29
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.Enginsight
Vendor | Product | Version |
---|---|---|
fasterxml | jackson-modules-java8 | 𝑥 < 2.9.8 |
oracle | clusterware | 12.1.0.2.0 |
oracle | database_server | 12.1.0.2 |
oracle | database_server | 12.2.0.1 |
oracle | global_lifecycle_management_opatch | 𝑥 < 11.2.0.3.23 |
oracle | global_lifecycle_management_opatch | 12.2.0.1.0 ≤ 𝑥 < 12.2.0.1.19 |
oracle | global_lifecycle_management_opatch | 13.9.4.0.0 ≤ 𝑥 < 13.9.4.2.1 |
oracle | nosql_database | 𝑥 < 19.3.12 |
netapp | active_iq_unified_manager | 7.3 ≤ |
netapp | active_iq_unified_manager | 7.3 ≤ |
netapp | active_iq_unified_manager | 9.5 ≤ |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References