CVE-2020-35490

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 94.17%
Affected Products (NVD)
VendorProductVersion
fasterxmljackson-databind
2.0.0 ≤
𝑥
< 2.9.10.8
netappservice_level_manager
-
debiandebian_linux
9.0
oracleagile_product_lifecycle_management
9.3.6
oracleapplication_testing_suite
13.3.0.1
oracleautovue_for_agile_product_lifecycle_management
21.0.2
oraclebanking_platform
2.6.2
oraclebanking_platform
2.7.0
oraclebanking_platform
2.7.1
oraclebanking_platform
2.8.0
oraclebanking_platform
2.9.0
oraclebanking_platform
2.10.0
oraclebanking_treasury_management
14.4
oraclebanking_virtual_account_management
14.2.0
oraclebanking_virtual_account_management
14.3.0
oraclebanking_virtual_account_management
14.5.0
oracleblockchain_platform
𝑥
≤ 21.1.2
oraclecommunications_cloud_native_core_policy
1.14.0
oraclecommunications_cloud_native_core_unified_data_repository
1.4.0
oraclecommunications_diameter_signaling_router
8.0.0 ≤
𝑥
≤ 8.5.0
oraclecommunications_evolved_communications_application_server
7.1
oraclecommunications_instant_messaging_server
10.0.1.5.0
oraclecommunications_interactive_session_recorder
6.3
oraclecommunications_interactive_session_recorder
6.4
oraclecommunications_offline_mediation_controller
12.0.0.3
oraclecommunications_pricing_design_center
12.0.0.4.0
oraclecommunications_services_gatekeeper
7.0
oraclecommunications_unified_inventory_management
7.4.1
oracledocumaker
12.6.3
oracledocumaker
12.6.4
oracleinsurance_policy_administration_j2ee
11.2.0
oracleretail_merchandising_system
15.0.3
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jackson-databind
bookworm
2.14.0-1
fixed
bullseye
2.12.1-1+deb11u1
fixed
bullseye (security)
2.12.1-1+deb11u1
fixed
sid
2.14.0-1
fixed
trixie
2.14.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jackson-databind
bionic
needed
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needed
oracular
ignored
plucky
ignored
questing
ignored
resolute
needed
trusty
needs-triage
xenial
needed