VDB

BDU%3A2019-01372

BDU%3A2019-01372 PUBLISHED CVSS 10 CRITICAL

Уязвимость библиотеки Jackson-databind, вызванная отсутствием защиты класса slf4j-ext от полиморфной десериализации, позволяющая нарушителю выполнить произвольный код

Risk Scores

CVSS 2.0
10

Affected Products

VendorProductVersions
Oracle Corp., FasterXML, LLC, Сообщество свободного программного обеспечения, Red Hat Inc.Primavera Unifier, WebCenter Portal, Jackson-databind, Oracle Retail Merchandising System, Oracle JDeveloper, Debian GNU/Linux, OpenShift Container Platform, Communications Billing and Revenue Management, NoSQL Database, Financial Services Analytical Applications Infrastructure, Enterprise Manager for Virtualization, Banking Platform

Timeline

  • Apr 12, 2019 CVE Published
  • Feb 20, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›