CVE-2018-19361
02.01.2019, 18:29
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fasterxml | jackson-databind | 2.6.0 ≤ 𝑥 ≤ 2.6.7.2 |
| fasterxml | jackson-databind | 2.7.0 ≤ 𝑥 < 2.7.9.5 |
| fasterxml | jackson-databind | 2.8.0 ≤ 𝑥 < 2.8.11.3 |
| fasterxml | jackson-databind | 2.9.0 ≤ 𝑥 < 2.9.8 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| oracle | business_process_management_suite | 12.1.3.0.0 |
| oracle | business_process_management_suite | 12.2.1.3.0 |
| oracle | primavera_p6_enterprise_project_portfolio_management | 17.7 ≤ 𝑥 ≤ 17.12 |
| oracle | primavera_p6_enterprise_project_portfolio_management | 15.1 |
| oracle | primavera_p6_enterprise_project_portfolio_management | 15.2 |
| oracle | primavera_p6_enterprise_project_portfolio_management | 16.1 |
| oracle | primavera_p6_enterprise_project_portfolio_management | 16.2 |
| oracle | primavera_p6_enterprise_project_portfolio_management | 18.8 |
| oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
| oracle | primavera_unifier | 16.1 |
| oracle | primavera_unifier | 16.2 |
| oracle | primavera_unifier | 18.8 |
| oracle | retail_workforce_management_software | 1.60.9.0.0 |
| oracle | webcenter_portal | 12.2.1.3.0 |
| redhat | automation_manager | 7.3.1 |
| redhat | decision_manager | 7.3.1 |
| redhat | jboss_bpm_suite | 6.4.11 |
| redhat | jboss_brms | 6.4.10 |
| redhat | openshift_container_platform | 3.11 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| jackson-databind |
|
Common Weakness Enumeration
References