CVE-2018-14718
02.01.2019, 18:29
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.Enginsight
Vendor | Product | Version |
---|---|---|
fasterxml | jackson-databind | 2.0.0 ≤ 𝑥 < 2.6.7.3 |
fasterxml | jackson-databind | 2.7.0 ≤ 𝑥 < 2.7.9.5 |
fasterxml | jackson-databind | 2.8.0 ≤ 𝑥 < 2.8.11.3 |
fasterxml | jackson-databind | 2.9.0 ≤ 𝑥 < 2.9.7 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
oracle | banking_platform | 2.5.0 |
oracle | banking_platform | 2.6.0 |
oracle | banking_platform | 2.6.1 |
oracle | banking_platform | 2.6.2 |
oracle | business_process_management_suite | 12.1.3.0.0 |
oracle | business_process_management_suite | 12.2.1.3.0 |
oracle | communications_billing_and_revenue_management | 7.5 |
oracle | communications_billing_and_revenue_management | 12.0 |
oracle | communications_instant_messaging_server | 10.0.1.3.0 |
oracle | enterprise_manager_for_virtualization | 13.2.2 |
oracle | enterprise_manager_for_virtualization | 13.2.3 |
oracle | enterprise_manager_for_virtualization | 13.3.1 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.2 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.3 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.4 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.5 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.7 |
oracle | global_lifecycle_management_opatch | 𝑥 < 11.2.0.3.23 |
oracle | global_lifecycle_management_opatch | 12.2.0.1.0 ≤ 𝑥 < 12.2.0.1.19 |
oracle | global_lifecycle_management_opatch | 13.9.4.0.0 ≤ 𝑥 < 13.9.4.2.1 |
oracle | jd_edwards_enterpriseone_orchestrator | 9.2 |
oracle | jd_edwards_enterpriseone_tools | 9.2 |
oracle | jdeveloper | 12.1.3.0.0 |
oracle | jdeveloper | 12.2.1.3.0 |
oracle | nosql_database | 𝑥 < 19.3.12 |
oracle | nosql_database | 19.3.12 |
oracle | primavera_p6_enterprise_project_portfolio_management | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_p6_enterprise_project_portfolio_management | 15.1 |
oracle | primavera_p6_enterprise_project_portfolio_management | 15.2 |
oracle | primavera_p6_enterprise_project_portfolio_management | 16.1 |
oracle | primavera_p6_enterprise_project_portfolio_management | 16.2 |
oracle | primavera_p6_enterprise_project_portfolio_management | 18.8 |
oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_unifier | 16.1 |
oracle | primavera_unifier | 16.2 |
oracle | primavera_unifier | 18.8 |
oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
oracle | retail_merchandising_system | 15.0 |
oracle | retail_merchandising_system | 16.0 |
oracle | retail_workforce_management_software | 1.60.9.0.0 |
oracle | siebel_engineering_-_installer_\&_deployment | 𝑥 ≤ 19.8 |
oracle | siebel_ui_framework | 𝑥 ≤ 19.10 |
oracle | webcenter_portal | 12.2.1.3.0 |
netapp | oncommand_workflow_automation | - |
netapp | snapcenter | - |
netapp | steelstore_cloud_integrated_storage | - |
redhat | openshift_container_platform | 3.11 ≤ 𝑥 < 3.11.153 |
redhat | openshift_container_platform | 4.6 ≤ 𝑥 < 4.6.26 |
redhat | openshift_container_platform | 3.10 |
redhat | openshift_container_platform | 4.1 ≤ 𝑥 < 4.1.18 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
jackson-databind |
|
Common Weakness Enumeration
References