CVE-2018-11307
09.07.2019, 16:15
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fasterxml | jackson-databind | 2.0.0 ≤ 𝑥 < 2.6.7.3 |
| fasterxml | jackson-databind | 2.7.0 ≤ 𝑥 < 2.7.9.4 |
| fasterxml | jackson-databind | 2.8.0 ≤ 𝑥 < 2.8.11.2 |
| fasterxml | jackson-databind | 2.9.0 ≤ 𝑥 < 2.9.6 |
| redhat | openshift_container_platform | 3.11 |
| redhat | openshift_container_platform | 4.1 |
| oracle | clusterware | 12.1.0.2.0 |
| oracle | communications_instant_messaging_server | 10.0.1.2.0 |
| oracle | global_lifecycle_management_opatch | 𝑥 < 11.2.0.3.23 |
| oracle | global_lifecycle_management_opatch | 12.2.0.1.0 ≤ 𝑥 < 12.2.0.1.19 |
| oracle | global_lifecycle_management_opatch | 13.9.4.0.0 ≤ 𝑥 < 13.9.4.2.1 |
| oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
| oracle | utilities_advanced_spatial_and_operational_analytics | 2.7.0.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| jackson-databind |
|
Common Weakness Enumeration
References