CVE-2019-17267
קריטית 9.8
תיאור (מקור, אנגלית)
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 5% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-502
מוצרים מושפעים
fasterxml: jackson-databind; netapp: active iq unified manager; netapp: oncommand api services; netapp: oncommand workflow automation; netapp: service level manager; netapp: steelstore cloud integrated storage; debian: debian linux; redhat: jboss enterprise application platform; redhat: enterprise linux; oracle: customer management and segmentation foundation; oracle: goldengate application adapters; oracle: retail customer management and segmentation foundation; oracle: weblogic server
קישורים
- https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3… PatchThird Party Advisory
- https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3… PatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3200 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0159 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445 Third Party Advisory
- https://github.com/FasterXML/jackson-databind/issues/2460 Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d8…