CVE-2018-12023
21.03.2019, 16:00
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.Enginsight
Vendor | Product | Version |
---|---|---|
fasterxml | jackson-databind | 2.7.0 ≤ 𝑥 < 2.7.9.4 |
fasterxml | jackson-databind | 2.8.0 ≤ 𝑥 < 2.8.11.2 |
fasterxml | jackson-databind | 2.9.0 ≤ 𝑥 < 2.9.6 |
debian | debian_linux | 9.0 |
oracle | jd_edwards_enterpriseone_tools | 9.2 |
oracle | retail_merchandising_system | 15.0 |
redhat | automation_manager | 7.3.1 |
redhat | decision_manager | 7.3.1 |
redhat | jboss_brms | 6.4.10 |
redhat | jboss_enterprise_application_platform | 7.2.0 |
redhat | openshift_container_platform | 3.11 |
redhat | single_sign-on | 7.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
jackson-databind |
|
Common Weakness Enumeration
References