CVE-2019-14439
30.07.2019, 11:15
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.Enginsight
Vendor | Product | Version |
---|---|---|
fasterxml | jackson-databind | 2.0.0 ≤ 𝑥 < 2.6.7.3 |
fasterxml | jackson-databind | 2.7.0 ≤ 𝑥 < 2.7.9.6 |
fasterxml | jackson-databind | 2.8.0 ≤ 𝑥 < 2.8.11.4 |
fasterxml | jackson-databind | 2.9.0 ≤ 𝑥 < 2.9.9.2 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
apache | drill | 1.16.0 |
redhat | jboss_middleware_text-only_advisories | 1.0 |
oracle | banking_platform | 2.4.0 |
oracle | banking_platform | 2.4.1 |
oracle | banking_platform | 2.5.0 |
oracle | banking_platform | 2.6.0 |
oracle | banking_platform | 2.6.1 |
oracle | banking_platform | 2.7.0 |
oracle | banking_platform | 2.7.1 |
oracle | communications_diameter_signaling_router | 8.0.0 |
oracle | communications_diameter_signaling_router | 8.1 |
oracle | communications_diameter_signaling_router | 8.2 |
oracle | communications_diameter_signaling_router | 8.2.1 |
oracle | communications_instant_messaging_server | 10.0.1.3.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.2 ≤ 𝑥 ≤ 8.0.8 |
oracle | global_lifecycle_management_opatch | 𝑥 < 11.2.0.3.23 |
oracle | global_lifecycle_management_opatch | 12.2.0.1.0 ≤ 𝑥 < 12.2.0.1.19 |
oracle | global_lifecycle_management_opatch | 13.9.4.0.0 ≤ 𝑥 < 13.9.4.2.1 |
oracle | global_lifecycle_management_opatch | 11.2.0.3.23 |
oracle | global_lifecycle_management_opatch | 13.9.4.2.1 |
oracle | goldengate_stream_analytics | 𝑥 < 19.1.0.0.1 |
oracle | jd_edwards_enterpriseone_orchestrator | 9.2 |
oracle | jd_edwards_enterpriseone_tools | 9.2 |
oracle | primavera_gateway | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_gateway | 15.2 |
oracle | primavera_gateway | 16.1 |
oracle | primavera_gateway | 16.2 |
oracle | primavera_gateway | 18.8.0 |
oracle | retail_customer_management_and_segmentation_foundation | 17.0 |
oracle | retail_xstore_point_of_service | 7.1 |
oracle | retail_xstore_point_of_service | 15.0 |
oracle | retail_xstore_point_of_service | 16.0 |
oracle | retail_xstore_point_of_service | 17.0 |
oracle | retail_xstore_point_of_service | 18.0 |
oracle | siebel_engineering_-_installer_\&_deployment | 𝑥 ≤ 19.8 |
oracle | siebel_ui_framework | 𝑥 ≤ 19.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References