CVE-2020-10672
18.03.2020, 22:15
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).Enginsight
Vendor | Product | Version |
---|---|---|
fasterxml | jackson-databind | 2.9.0 ≤ 𝑥 < 2.9.10.4 |
debian | debian_linux | 8.0 |
netapp | steelstore_cloud_integrated_storage | - |
oracle | agile_plm | 9.3.6 |
oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
oracle | banking_digital_experience | 18.1 |
oracle | banking_digital_experience | 18.2 |
oracle | banking_digital_experience | 18.3 |
oracle | banking_digital_experience | 19.1 |
oracle | banking_digital_experience | 19.2 |
oracle | banking_digital_experience | 20.1 |
oracle | banking_platform | 2.4.0 ≤ 𝑥 ≤ 2.9.0 |
oracle | communications_calendar_server | 8.0.0.4.0 |
oracle | communications_contacts_server | 8.0.0.4.0 |
oracle | communications_contacts_server | 8.0.0.5.0 |
oracle | communications_diameter_signaling_router | 8.0.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_element_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_evolved_communications_application_server | 7.1 |
oracle | communications_instant_messaging_server | 10.0.1.4.0 |
oracle | communications_network_charging_and_control | 12.0.0 ≤ 𝑥 ≤ 12.0.3 |
oracle | communications_network_charging_and_control | 6.0.1 |
oracle | communications_session_report_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | communications_session_route_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.2 |
oracle | enterprise_manager_base_platform | 13.3.0.0 |
oracle | enterprise_manager_base_platform | 13.4.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 ≤ 𝑥 ≤ 8.1.0 |
oracle | financial_services_institutional_performance_analytics | 8.0.6 |
oracle | financial_services_institutional_performance_analytics | 8.0.7 |
oracle | financial_services_institutional_performance_analytics | 8.1.0 |
oracle | financial_services_price_creation_and_discovery | 8.0.6 |
oracle | financial_services_price_creation_and_discovery | 8.0.7 |
oracle | financial_services_retail_customer_analytics | 8.0.6 |
oracle | global_lifecycle_management_opatch | 𝑥 < 12.2.0.1.20 |
oracle | insurance_policy_administration_j2ee | 11.0.2.25 |
oracle | insurance_policy_administration_j2ee | 11.1.0.15 |
oracle | jd_edwards_enterpriseone_orchestrator | 𝑥 < 9.2.4.2 |
oracle | jd_edwards_enterpriseone_tools | 𝑥 < 9.2.4.2 |
oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_unifier | 16.1 |
oracle | primavera_unifier | 16.2 |
oracle | primavera_unifier | 18.8 |
oracle | primavera_unifier | 19.12 |
oracle | retail_merchandising_system | 15.0 |
oracle | retail_sales_audit | 14.1 |
oracle | retail_service_backbone | 14.1 |
oracle | retail_service_backbone | 15.0 |
oracle | retail_service_backbone | 16.0 |
oracle | retail_xstore_point_of_service | 15.0 |
oracle | retail_xstore_point_of_service | 16.0 |
oracle | retail_xstore_point_of_service | 17.0 |
oracle | retail_xstore_point_of_service | 18.0 |
oracle | retail_xstore_point_of_service | 19.0 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References